Description
Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the db_id parameter to visitorupload.php, as demonstrated using phpinfo and include function calls.
Exploits (1)
References (5)
Scores
EPSS
0.0279
EPSS Percentile
86.1%
Details
Status
published
Products (2)
indexcor/ezdatabase
2.0
indexcor/ezdatabase
2.1.2
Published
Jan 15, 2006
Tracked Since
Feb 18, 2026