CVE-2006-1090

PunBB 1.2.10 - Denial of Service via User Registration Flood

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-1090. PoCs published by K4P0.

AI-analyzed exploit summary This exploit targets a Denial of Service (DoS) vulnerability in PunBB 2.0.10 by flooding the registration endpoint with repeated HTTP POST requests. It establishes multiple connections to the target server and sends malformed registration data to exhaust resources.

Description

register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user registrations.

Exploits (1)

exploitdb WORKING POC VERIFIED
by K4P0 · cdosphp
https://www.exploit-db.com/exploits/1517

This exploit targets a Denial of Service (DoS) vulnerability in PunBB 2.0.10 by flooding the registration endpoint with repeated HTTP POST requests. It establishes multiple connections to the target server and sends malformed registration data to exhaust resources.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: PunBB 2.0.10
No auth needed
Prerequisites: Network access to the target server · Target running PunBB 2.0.10
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Various Sources x_refsource_confirm
http://www.punbb.org/changelogs/1.2.10_to_1.2.11.txt
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0773
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/24837

Scores

EPSS 0.0361
EPSS Percentile 88.0%

Details

Status published
Products (1)
punbb/punbb 1.2.10
Published Mar 09, 2006
Tracked Since Feb 18, 2026