CVE-2006-1481

php_ticket 0.71 - Authenticated SQL Injection via search.php frm_search_in Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-1481. PoCs published by undefined1_.

AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in php ticket <= 0.71, allowing an attacker to dump user credentials from the database. It uses a UNION-based SQLi to extract usernames and passwords encrypted with MySQL's PASSWORD() function.

Description

SQL injection vulnerability in search.php in PHP Ticket 0.71 allows remote authenticated users to execute arbitrary SQL commands and obtain usernames and passwords via the frm_search_in parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by undefined1_ · perlwebappsphp
https://www.exploit-db.com/exploits/1609

This exploit targets a SQL injection vulnerability in php ticket <= 0.71, allowing an attacker to dump user credentials from the database. It uses a UNION-based SQLi to extract usernames and passwords encrypted with MySQL's PASSWORD() function.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: php ticket <= 0.71
Auth required
Prerequisites: Valid user credentials for authentication · Access to the search.php endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25436
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17229
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/1609
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1106
Exploit third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19412

Scores

EPSS 0.0100
EPSS Percentile 58.1%

Details

Status published
Products (3)
php_ticket/php_ticket 0.5
php_ticket/php_ticket 0.6
php_ticket/php_ticket < 0.71
Published Mar 29, 2006
Tracked Since Feb 18, 2026