CVE-2006-5508

WoltLab Burning Book 1.1.2 - SQL Injection via n Parameter or User-Agent Header

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-5508.

AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in WoltLab Burning Book <=1.1.2 by injecting malicious SQL into the 'n' parameter of the addentry.php endpoint. It creates a new template record that executes arbitrary PHP code (phpinfo()) via SQL injection, demonstrating remote code execution.

Description

Multiple SQL injection vulnerabilities in addentry.php in WoltLab Burning Book 1.1.2 allow remote attackers to execute arbitrary SQL commands via (1) the n parameter and (2) the User-Agent HTTP header.

Exploits (1)

exploitdb WORKING POC
perlwebappsphp
https://www.exploit-db.com/exploits/2579

This Perl script exploits a SQL injection vulnerability in WoltLab Burning Book <=1.1.2 by injecting malicious SQL into the 'n' parameter of the addentry.php endpoint. It creates a new template record that executes arbitrary PHP code (phpinfo()) via SQL injection, demonstrating remote code execution.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: WoltLab Burning Book <=1.1.2
No auth needed
Prerequisites: Network access to the target application · The addentry.php endpoint must be accessible
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1774
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4062
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/448796/100/100/threaded
Various Sources x_refsource_misc
http://www.security.nnov.ru/Odocument711.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22442

Scores

EPSS 0.0106
EPSS Percentile 60.3%

Details

Status published
Products (1)
woltlab/burning_book 1.1.2
Published Oct 25, 2006
Tracked Since Feb 18, 2026