CVE-2006-2459

PHP-Fusion <= 6.00.307 - Authenticated SQL Injection via srch_where Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-2459. PoCs published by rgod.

AI-analyzed exploit summary This exploit leverages a SQL injection vulnerability in PHP-Fusion <= v6.00.306 to disclose admin credentials by injecting malicious SQL queries into the 'srch_where' parameter. It requires valid user credentials to authenticate and extract the admin username and password hash.

Description

SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL commands via the srch_where parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by rgod · phpwebappsphp
https://www.exploit-db.com/exploits/1796

This exploit leverages a SQL injection vulnerability in PHP-Fusion <= v6.00.306 to disclose admin credentials by injecting malicious SQL queries into the 'srch_where' parameter. It requires valid user credentials to authenticate and extract the admin username and password hash.

Classification
Working Poc 100%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: PHP-Fusion <= v6.00.306
Auth required
Prerequisites: Valid user credentials · Access to the target server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/26491
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18009
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/922
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/434162/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/25542
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20129
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016111
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/1839

Scores

EPSS 0.0207
EPSS Percentile 78.9%

Details

Status published
Products (2)
php_fusion/php_fusion 6.00.306
php_fusion/php_fusion 6.00.307
Published May 19, 2006
Tracked Since Feb 18, 2026