CVE Vulnerabilities

CVE-2006-1094

Published: Mar 09, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) info_db.php or (2) database.php.

Affected Software

NameVendorStart VersionEnd Version
Datenbank_moduleDatenbank_module*2.7 (including)
Burning_boardWoltlab1.1.1 (including)1.1.1 (including)
Burning_boardWoltlab2.0_beta_3 (including)2.0_beta_3 (including)
Burning_boardWoltlab2.0_beta_4 (including)2.0_beta_4 (including)
Burning_boardWoltlab2.0_beta_5 (including)2.0_beta_5 (including)
Burning_boardWoltlab2.0_rc1 (including)2.0_rc1 (including)
Burning_boardWoltlab2.0_rc2 (including)2.0_rc2 (including)
Burning_boardWoltlab2.2.2 (including)2.2.2 (including)
Burning_boardWoltlab2.3.1 (including)2.3.1 (including)
Burning_boardWoltlab2.3.3 (including)2.3.3 (including)
Burning_boardWoltlab2.4 (including)2.4 (including)
Burning_boardWoltlab2.5 (including)2.5 (including)
Burning_boardWoltlab2.6 (including)2.6 (including)
Burning_boardWoltlab2.7 (including)2.7 (including)

References