CVE-2006-2065

PHPSurveyor <= 0.995 - SQL Injection via surveyid Cookie

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-2065. PoCs published by rgod.

AI-analyzed exploit summary This exploit targets PHPSurveyor <= 0.995 by injecting malicious PHP code into log files via HTTP headers and then triggering its execution through a SQL injection in the 'surveyid' parameter. It bypasses magic_quotes_gpc and attempts multiple log file paths for inclusion.

Description

SQL injection vulnerability in save.php in PHPSurveyor 0.995 and earlier allows remote attackers to execute arbitrary SQL commands via the surveyid cookie. NOTE: this issue could be leveraged to execute arbitrary PHP code, as demonstrated by inserting directory traversal sequences into the database, which are then processed by the thissurvey['language'] variable.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1701

This exploit targets PHPSurveyor <= 0.995 by injecting malicious PHP code into log files via HTTP headers and then triggering its execution through a SQL injection in the 'surveyid' parameter. It bypasses magic_quotes_gpc and attempts multiple log file paths for inclusion.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: PHPSurveyor <= 0.995
No auth needed
Prerequisites: At least one row in the 'surveys' table · Write access to log files · PHP environment with accessible logs
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17633
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/431508/100/0/threaded
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19761
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1015970
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25970
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/24787
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1451

Scores

EPSS 0.0171
EPSS Percentile 74.3%

Details

Status published
Products (9)
phpsurveyor/phpsurveyor 0.96_beta
phpsurveyor/phpsurveyor 0.97_beta
phpsurveyor/phpsurveyor 0.98_beta
phpsurveyor/phpsurveyor 0.98_stable
phpsurveyor/phpsurveyor 0.99
phpsurveyor/phpsurveyor 0.991
phpsurveyor/phpsurveyor 0.992
phpsurveyor/phpsurveyor 0.993
phpsurveyor/phpsurveyor 0.995
Published Apr 27, 2006
Tracked Since Feb 18, 2026