CVE-2006-6289
Woltlab Burning Board (wBB) Lite 1.0.2 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via…
Does this matter?
Lower severity and a low EPSS score (2.09%). Track it; it rarely justifies an emergency change on its own.
Description
Woltlab Burning Board (wBB) Lite 1.0.2 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allows remote attackers to execute arbitrary SQL commands via the wbb_userid parameter to the top-level URI. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in wBB Lite.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.09% probability · 81th percentile
- CISA KEV
- Not listed
- Affected
- woltlab/burning board lite
- Source
- cve@mitre.org
References
- http://retrogod.altervista.org/wbblite_102_sql.htmlExploit
- http://www.securityfocus.com/archive/1/452561/100/0/threaded
- http://www.securityfocus.com/bid/21265
- http://retrogod.altervista.org/wbblite_102_sql.htmlExploit
- http://www.securityfocus.com/archive/1/452561/100/0/threaded
- http://www.securityfocus.com/bid/21265
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.