CVE-2006-1395

Cholod MySQL Based Message Board - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-1395. PoCs published by kspecial.

AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in MySQL Based Message Board, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could exploit this by manipulating query parameters.

Description

SQL injection vulnerability in mb.cgi in Cholod MySQL Based Message Board allows remote attackers to execute arbitrary SQL commands via unspecified vectors in a showmessage action, possibly the username parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

Exploits (1)

exploitdb WRITEUP VERIFIED
by kspecial · textwebappscgi
https://www.exploit-db.com/exploits/27464

The provided text describes an SQL injection vulnerability in MySQL Based Message Board, where user-supplied input is not properly sanitized. The example URL demonstrates how an attacker could exploit this by manipulating query parameters.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: MySQL Based Message Board (version unspecified)
No auth needed
Prerequisites: Access to the vulnerable web application
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19439
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25520
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1153
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17224

Scores

EPSS 0.0114
EPSS Percentile 63.2%

Details

Status published
Products (1)
cholod/mysql_based_message_board
Published Mar 26, 2006
Tracked Since Feb 18, 2026