CVE-2006-5509 Information

Description

Eval injection vulnerability in addentry.php in WoltLab Burning Book 1.1.2 allows remote attackers to execute arbitrary PHP code via crafted POST requests that store PHP code in a database that is later processed by eval as demonstrated using SQL injection via the n parameter.

Reference

http://secunia.com/advisories/22442 http://securityreason.com/securityalert/1774 http://www.security.nnov.ru/Odocument711.html http://www.securityfocus.com/archive/1/448796/100/100/threaded http://www.securityfocus.com/bid/20563 http://www.vupen.com/english/advisories/2006/4062 https://exchange.xforce.ibmcloud.com/vulnerabilities/29599

Share on: