CVE-2006-1094: SQL Injection
SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) infodb.php or (2) database.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1094?
CVE-2006-1094 has been rated as a high severity vulnerability due to its potential for remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2006-1094?
To fix CVE-2006-1094, upgrade to a version of Woltlab Burning Board later than 2.7 and apply all relevant security patches.
Which versions of Woltlab Burning Board are affected by CVE-2006-1094?
CVE-2006-1094 affects Woltlab Burning Board versions 1.1.1, 2.0 Beta 3, 2.0 Beta 4, 2.0 Beta 5, and 2.7 and earlier versions.
Can CVE-2006-1094 be exploited remotely?
Yes, CVE-2006-1094 can be exploited remotely due to the SQL injection vulnerability in the identified parameters.
Is the Datenbank MOD also vulnerable to CVE-2006-1094?
Yes, the Datenbank MOD version 2.7 and earlier is also vulnerable to CVE-2006-1094.