CVE-2006-2065
Phpsurveyor - SQL Injection
Title source: ruleDescription
SQL injection vulnerability in save.php in PHPSurveyor 0.995 and earlier allows remote attackers to execute arbitrary SQL commands via the surveyid cookie. NOTE: this issue could be leveraged to execute arbitrary PHP code, as demonstrated by inserting directory traversal sequences into the database, which are then processed by the thissurvey['language'] variable.
Exploits (1)
References (8)
Scores
EPSS
0.0115
EPSS Percentile
78.5%
Details
Status
published
Products (9)
phpsurveyor/phpsurveyor
0.96_beta
phpsurveyor/phpsurveyor
0.97_beta
phpsurveyor/phpsurveyor
0.98_beta
phpsurveyor/phpsurveyor
0.98_stable
phpsurveyor/phpsurveyor
0.99
phpsurveyor/phpsurveyor
0.991
phpsurveyor/phpsurveyor
0.992
phpsurveyor/phpsurveyor
0.993
phpsurveyor/phpsurveyor
0.995
Published
Apr 27, 2006
Tracked Since
Feb 18, 2026