CVE-2006-2040

photokorn 1.53 and 1.542 - SQL Injection via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2006-2040. PoCs published by Dr.Jr7.

AI-analyzed exploit summary The provided text describes a SQL injection vulnerability in Photokorn, where the 'cat' parameter in 'print.php' is not properly sanitized. It lacks executable exploit code but references a known CVE and vulnerability details.

Description

Multiple SQL injection vulnerabilities in photokorn 1.53 and 1.542 allow remote attackers to execute arbitrary SQL commands via the (1) cat, (2) pic and (3) page parameter in index.php; (4) id parameter in postcard.php; and (5) cat parameter in print.php.

Exploits (3)

exploitdb WRITEUP VERIFIED
by Dr.Jr7 · textwebappsphp
https://www.exploit-db.com/exploits/27733

The provided text describes a SQL injection vulnerability in Photokorn, where the 'cat' parameter in 'print.php' is not properly sanitized. It lacks executable exploit code but references a known CVE and vulnerability details.

Classification
Writeup 80%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Photokorn (version not specified)
No auth needed
Prerequisites: Access to the vulnerable endpoint
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Dr.Jr7 · textwebappsphp
https://www.exploit-db.com/exploits/27731

The provided text describes SQL injection vulnerabilities in Photokorn, detailing vulnerable parameters in URLs. It does not include executable exploit code but references the vulnerability's impact and attack vectors.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Photokorn (version not specified)
No auth needed
Prerequisites: Access to the vulnerable Photokorn web application
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Dr.Jr7 · textwebappsphp
https://www.exploit-db.com/exploits/27732

The provided text describes a SQL injection vulnerability in Photokorn, where the 'id' parameter in 'postcard.php' is not properly sanitized. It includes a generic example URL for exploitation but lacks actual exploit code.

Classification
Writeup 80%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Photokorn (version not specified)
No auth needed
Prerequisites: Access to the vulnerable 'postcard.php' endpoint
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19836
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/24982
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/431982/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/24983
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1525
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/26066
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/24981
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17683
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/789

Scores

EPSS 0.0389
EPSS Percentile 89.2%

Details

Status published
Products (2)
photokorn/photokorn 1.53
photokorn/photokorn 1.542
Published Apr 26, 2006
Tracked Since Feb 18, 2026