peter bassill · operator
$ cve CVE-2006-3994 JSON

CVE-2006-3994 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 3.8% (pctl 90)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in the u2u_send_recp function in u2u.inc.php in XMB (aka extreme message board) 1.9.6 Alpha and earlier allows remote attackers to execute arbitrary SQL commands via the u2uid parameter to u2u.php, which is directly accessed from $_POST and bypasses the protection scheme.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS3.81% — more likely to be exploited than 90% of all CVEs
On CISA KEVno
Public exploityes
Published2006-08-05
Last modified2026-06-16

Affected (1)

VendorProduct
xmb softwarexmb forum

Public exploits

SourceTitleDate
exploit-dbXMB 1.9.6 - 'mq=off' 'u2uid' SQL Injection2006-08-01

References

→ the Explorer  ·  watch your stack  ·  NVD