CVE-2006-6369

Invision Community Blog Mod 1.2.4 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-6369. PoCs published by anonymous.

AI-analyzed exploit summary This exploit leverages a SQL injection vulnerability in the blog entry preview functionality to extract user password hashes from the database. The attacker manipulates the 'eid' parameter to perform a UNION-based SQL injection, retrieving sensitive information.

Description

SQL injection vulnerability in lib/entry_reply_entry.php in Invision Community Blog Mod 1.2.4 allows remote attackers to execute arbitrary SQL commands via the eid parameter, when accessed through the "Preview message" functionality.

Exploits (1)

exploitdb WORKING POC VERIFIED
by anonymous · textwebappsphp
https://www.exploit-db.com/exploits/2877

This exploit leverages a SQL injection vulnerability in the blog entry preview functionality to extract user password hashes from the database. The attacker manipulates the 'eid' parameter to perform a UNION-based SQL injection, retrieving sensitive information.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Invision Power Board (IPB) Blog
No auth needed
Prerequisites: Access to a blog entry with reply functionality · Knowledge of a valid user ID
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/453159/100/100/threaded
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4820
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/453126/100/100/threaded

Scores

EPSS 0.0103
EPSS Percentile 59.1%

Details

Status published
Products (1)
invision_power_services/invision_community_blog 1.2.4
Published Dec 07, 2006
Tracked Since Feb 18, 2026