CVE-2009-2308
Status: ModifiedHigh (7.5)—💥 Exploit
Multiple SQL injection vulnerabilities in affiliates.php in the Affiliation (aka Affiliates) module 1.1.0 and earlier for PunBB allow remote attackers to execute arbitrary SQL commands via the (1) in or (2) out parameter.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.18%
- Percentile among all scored CVEs: 67
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · PunBB Affiliates Mod 1.1 - Blind SQL Injection (6/30/2009)
Affected technologies (1)
CWEs
- CWE-89
References
- http://packetstormsecurity.org/0906-exploits/punbbaffiliations-blindsql.txt
- http://packetstormsecurity.org/0906-exploits/punbbaffiliationsin-blindsql.txt
- http://secunia.com/advisories/35654
- http://www.exploit-db.com/exploits/9055
- http://www.osvdb.org/55478
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51437
- http://packetstormsecurity.org/0906-exploits/punbbaffiliations-blindsql.txt
- http://packetstormsecurity.org/0906-exploits/punbbaffiliationsin-blindsql.txt
- http://secunia.com/advisories/35654
- http://www.exploit-db.com/exploits/9055
- http://www.osvdb.org/55478
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51437
Raw JSON (NVD)
Show
{
"id": "CVE-2009-2308",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-07-02T10:30:00.593",
"references": [
{
"url": "http://packetstormsecurity.org/0906-exploits/punbbaffiliations-blindsql.txt",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.org/0906-exploits/punbbaffiliationsin-blindsql.txt",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/35654",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.exploit-db.com/exploits/9055",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/55478",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/51437",
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.org/0906-exploits/punbbaffiliations-blindsql.txt",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://packetstormsecurity.org/0906-exploits/punbbaffiliationsin-blindsql.txt",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/35654",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.exploit-db.com/exploits/9055",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/55478",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/51437",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple SQL injection vulnerabilities in affiliates.php in the Affiliation (aka Affiliates) module 1.1.0 and earlier for PunBB allow remote attackers to execute arbitrary SQL commands via the (1) in or (2) out parameter."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades de inyección SQL en affiliates.php del módulo Affiliation (también conocido como Affiliates) v1.1.0 y anteriores para PunBB, permite a atacantes remotos ejecutar comandos SQL de su elección a través de los parámetros (1) \"in\" o (2) \"out\"."
}
],
"lastModified": "2026-06-16T23:09:11.083",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:punbb:punbb:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F9B94FB2-2C83-42D6-BECC-D39E97594CA4"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:punres:affiliates_mod:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4359BE72-D905-4D00-B08A-6BD27CE07FE2",
"versionEndIncluding": "1.1.0"
},
{
"criteria": "cpe:2.3:a:punres:affiliates_mod:1.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "54BF6E51-01A6-417D-8F6D-86523D6E87A6"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}