CVE-2006-6280

Oxygen O2PHP BB <1.1.3 - SQL Injection

Title source: llm

Description

SQL injection vulnerability in viewthread.php in Oxygen (O2PHP Bulletin Board) 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter, a different vector than CVE-2006-1572.

Exploits (1)

exploitdb WORKING POC VERIFIED
by DarkFig · phpwebappsphp
https://www.exploit-db.com/exploits/2810

Scores

EPSS 0.0044
EPSS Percentile 62.9%

Classification

Status draft

Affected Products (1)

o2php.com/oxygen < 1.1.3

Timeline

Published Dec 04, 2006
Tracked Since Feb 18, 2026