CVE-2006-5029: SQL Injection
SQL injection vulnerability in thread.php in WoltLab Burning Board (wBB) 2.3.x allows remote attackers to obtain the version numbers of PHP, MySQL, and wBB via the page parameter. NOTE: this issue might be a forced SQL error. Also, the original report was disputed by a third party for 2.3.3 and 2.3.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5029?
CVE-2006-5029 has a severity level that can lead to exposure of sensitive information, particularly version numbers of software components.
How do I fix CVE-2006-5029?
To fix CVE-2006-5029, it is recommended to upgrade WoltLab Burning Board to a version that is not vulnerable, such as versions later than 2.3.5.
Which versions of WoltLab Burning Board are affected by CVE-2006-5029?
CVE-2006-5029 affects WoltLab Burning Board versions 2.3.0 through 2.3.5.
Can CVE-2006-5029 lead to remote attacks?
Yes, CVE-2006-5029 allows remote attackers to exploit the vulnerability to obtain critical information.
Is CVE-2006-5029 a widespread vulnerability?
CVE-2006-5029 is considered a serious vulnerability due to the common use of the affected WoltLab Burning Board software in various communities.