CVE-2006-5509

Woltlab Burning Book - SQL Injection

Title source: rule

Description

Eval injection vulnerability in addentry.php in WoltLab Burning Book 1.1.2 allows remote attackers to execute arbitrary PHP code via crafted POST requests that store PHP code in a database that is later processed by eval, as demonstrated using SQL injection via the n parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ShAnKaR · perlwebappsphp
https://www.exploit-db.com/exploits/2579

Scores

EPSS 0.0133
EPSS Percentile 80.0%

Details

Status published
Products (1)
woltlab/burning_book 1.1.2
Published Oct 25, 2006
Tracked Since Feb 18, 2026