peter bassill · operator
$ cve CVE-2009-2111 JSON

CVE-2009-2111 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 3.7% (pctl 90)

Patch early

A public exploit exists.

Description

Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP code via a crafted (1) url and (2) location parameter.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS3.75% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2009-06-18
Last modified2026-06-16

Affected (1)

VendorProduct
jnmsolutionsdb top sites

Public exploits

SourceTitleDate
exploit-dbDB Top Sites 1.0 - Remote Command Execution2009-06-15

References

→ the Explorer  ·  watch your stack  ·  NVD