CVE-2006-5236

4homepages 4images - SQL Injection

Title source: rule

Description

SQL injection vulnerability in search.php in 4images 1.7.x allows remote authenticated users to execute arbitrary SQL commands via the search_user parameter.

Exploits (2)

exploitdb WRITEUP VERIFIED
by Master Mind · textwebappsphp
https://www.exploit-db.com/exploits/10572
exploitdb WORKING POC VERIFIED
by Synsta · phpwebappsphp
https://www.exploit-db.com/exploits/2487

Scores

EPSS 0.1086
EPSS Percentile 93.4%

Details

Status published
Products (2)
4homepages/4images 1.7.1
4homepages/4images 1.7.3
Published Oct 11, 2006
Tracked Since Feb 18, 2026