Unrated severityNVD Advisory· Published Oct 25, 2006· Updated Apr 23, 2026
CVE-2006-5509
CVE-2006-5509
Description
Eval injection vulnerability in addentry.php in WoltLab Burning Book 1.1.2 allows remote attackers to execute arbitrary PHP code via crafted POST requests that store PHP code in a database that is later processed by eval, as demonstrated using SQL injection via the n parameter.
Affected products
1- cpe:2.3:a:woltlab:burning_book:1.1.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- secunia.com/advisories/22442nvd
- securityreason.com/securityalert/1774nvd
- www.security.nnov.ru/Odocument711.htmlnvd
- www.securityfocus.com/archive/1/448796/100/100/threadednvd
- www.securityfocus.com/bid/20563nvd
- www.vupen.com/english/advisories/2006/4062nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/29599nvd
News mentions
0No linked articles in our index yet.