Vulnerability Details CVE-2006-1094
SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) info_db.php or (2) database.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.014
EPSS Ranking 79.2%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2006-1094
-
cpe:2.3:a:datenbank_module:datenbank_module:*
-
cpe:2.3:a:woltlab:burning_board:1.1.1
-
cpe:2.3:a:woltlab:burning_board:2.0_beta_3
-
cpe:2.3:a:woltlab:burning_board:2.0_beta_4
-
cpe:2.3:a:woltlab:burning_board:2.0_beta_5
-
cpe:2.3:a:woltlab:burning_board:2.0_rc1
-
cpe:2.3:a:woltlab:burning_board:2.0_rc2
-
cpe:2.3:a:woltlab:burning_board:2.2.2
-
cpe:2.3:a:woltlab:burning_board:2.3.1
-
cpe:2.3:a:woltlab:burning_board:2.3.3
-
cpe:2.3:a:woltlab:burning_board:2.4
-
cpe:2.3:a:woltlab:burning_board:2.5
-
cpe:2.3:a:woltlab:burning_board:2.6
-
cpe:2.3:a:woltlab:burning_board:2.7