22442Third-party advisory
http://secunia.com/advisories/22442 CVE-2006-5509
WoltLab Burning Book 1.1.2 - SQL Injection
Record summary
CVE-2006-5509 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Eval injection vulnerability in addentry.php in WoltLab Burning Book 1.1.2 allows remote attackers to execute arbitrary PHP code via crafted POST requests that store PHP code in a database that is later processed by eval, as demonstrated using SQL injection via the n parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWoltLab Burning Book 1.1.2 - SQL InjectionExploitDB exploitby ShAnKaRNot analyzed1 file
References
81774Third-party advisory
http://securityreason.com/securityalert/1774 security.nnov.ru
http://www.security.nnov.ru/Odocument711.html 20061016 :ShAnKaR: WoltLab Burning Book <=1.1.2 multiple vulnerabilitiesmailing list
http://www.securityfocus.com/archive/1/448796/100/100/threaded 20563vdb entry
http://www.securityfocus.com/bid/20563 ADV-2006-4062vdb entry
http://www.vupen.com/english/advisories/2006/4062 wburningbook-addentry-command-execution(29599)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/29599 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-5509