CVE-2006-2065

Phpsurveyor - SQL Injection

Title source: rule

Description

SQL injection vulnerability in save.php in PHPSurveyor 0.995 and earlier allows remote attackers to execute arbitrary SQL commands via the surveyid cookie. NOTE: this issue could be leveraged to execute arbitrary PHP code, as demonstrated by inserting directory traversal sequences into the database, which are then processed by the thissurvey['language'] variable.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1701

Scores

EPSS 0.0115
EPSS Percentile 78.5%

Details

Status published
Products (9)
phpsurveyor/phpsurveyor 0.96_beta
phpsurveyor/phpsurveyor 0.97_beta
phpsurveyor/phpsurveyor 0.98_beta
phpsurveyor/phpsurveyor 0.98_stable
phpsurveyor/phpsurveyor 0.99
phpsurveyor/phpsurveyor 0.991
phpsurveyor/phpsurveyor 0.992
phpsurveyor/phpsurveyor 0.993
phpsurveyor/phpsurveyor 0.995
Published Apr 27, 2006
Tracked Since Feb 18, 2026