CVE-2006-1094 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.4% (pctl 84)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) info_db.php or (2) database.php.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.41% — more likely to be exploited than 84% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-03-09 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| datenbank module | datenbank module |
| woltlab | burning board |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Woltlab Burning Board 2.x - Datenbank MOD 'fileid' SQL Injection | 2006-03-01 |
References
- http://www.nukedx.com/?viewdoc=17
- http://www.osvdb.org/23808
- http://www.osvdb.org/23810
- http://www.securityfocus.com/archive/1/426583
- http://www.securityfocus.com/bid/16914
- http://www.nukedx.com/?viewdoc=17
- http://www.osvdb.org/23808
- http://www.osvdb.org/23810
- http://www.securityfocus.com/archive/1/426583
- http://www.securityfocus.com/bid/16914
→ the Explorer · watch your stack · NVD