CVE-2006-5509: SQL Injection
Eval injection vulnerability in addentry.php in WoltLab Burning Book 1.1.2 allows remote attackers to execute arbitrary PHP code via crafted POST requests that store PHP code in a database that is later processed by eval, as demonstrated using SQL injection via the n parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5509?
The severity of CVE-2006-5509 is classified as high due to the potential for remote code execution.
How do I fix CVE-2006-5509?
To fix CVE-2006-5509, it is recommended to upgrade to WoltLab Burning Book version 1.1.3 or later.
What is the impact of CVE-2006-5509?
CVE-2006-5509 allows remote attackers to execute arbitrary PHP code on the server due to eval injection vulnerabilities.
Who is affected by CVE-2006-5509?
CVE-2006-5509 affects users of WoltLab Burning Book version 1.1.2.
What type of attack is CVE-2006-5509 associated with?
CVE-2006-5509 is associated with remote code execution attacks through crafted POST requests.