CVE-2006-0520

Dragoran Portal module 1.3 - SQL Injection via Site Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-0520. PoCs published by SkOd.

AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in IPB Portal 1.3, allowing an attacker to extract MD5 password hashes from the database by manipulating the 'site' parameter in a UNION-based SQL injection attack.

Description

SQL injection vulnerability index.php in Dragoran Portal module 1.3 for Invision Power Board (IPB) allows remote attackers to execute arbitrary SQL commands via the site parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Exploits (1)

exploitdb WORKING POC VERIFIED
by SkOd · perlwebappsphp
https://www.exploit-db.com/exploits/1461

This exploit targets a SQL injection vulnerability in IPB Portal 1.3, allowing an attacker to extract MD5 password hashes from the database by manipulating the 'site' parameter in a UNION-based SQL injection attack.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: IPB Portal 1.3 (Invision Power Board plugin)
No auth needed
Prerequisites: Target must be running IPB Portal 1.3 · Network access to the target web server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0396
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16447
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/22851
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/24404
Exploit, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18664

Scores

EPSS 0.0114
EPSS Percentile 62.3%

Details

Status published
Products (1)
dragoran/portal_module 1.3
Published Feb 02, 2006
Tracked Since Feb 18, 2026