CVE-2006-6756

Ixprim CMS 1.2 - Unauthenticated Brute Force Attack via Guessable IXP_CODE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-6756. PoCs published by DarkFig.

AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability in Ixprim 1.2 CMS by targeting the 'story_id' parameter in 'ixm_ixpnews.php'. It extracts administrator credentials, password hashes, and the confidential IXP code via time-based blind SQLi techniques.

Description

The code function in install.fct.php in Ixprim 1.2 produces a guessable value of the confidential IXP_CODE in mainfile.php, which might allow remote attackers to gain access to the administration panel via a brute force attack.

Exploits (1)

exploitdb WORKING POC VERIFIED
by DarkFig · perlwebappsphp
https://www.exploit-db.com/exploits/2975

This Perl script exploits a blind SQL injection vulnerability in Ixprim 1.2 CMS by targeting the 'story_id' parameter in 'ixm_ixpnews.php'. It extracts administrator credentials, password hashes, and the confidential IXP code via time-based blind SQLi techniques.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Ixprim CMS 1.2
No auth needed
Prerequisites: Target must have at least one comment posted · LOAD_FILE privilege for retrieving the IXP code
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/31142
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/455084/100/0/threaded
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/2975
Exploit x_refsource_misc
http://acid-root.new.fr/poc/16061221.txt
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/2073

Scores

EPSS 0.0224
EPSS Percentile 80.5%

Details

Status published
Products (1)
ixprim/ixprim_cms 1.2
Published Dec 27, 2006
Tracked Since Feb 18, 2026