AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2006-1104

HIGH · CVSS 7.5 EPSS 1.48%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2006-03-09 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It may be remotely exploitable. It involves a SQL injection risk.

CVE
CVE-2006-1104
Severity
HIGH
CVSS
7.5
EPSS
1.48%

Original NVD Description

Multiple SQL injection vulnerabilities in Pixelpost 1.5 beta 1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the showimage parameter in index.php; and the (2) USER_AGENT, (3) HTTP_REFERER, and (4) HTTP_HOST HTTP header fields as used in the book_vistor function in includes/functions.php. NOTE: the vendor has disputed some issues from the original disclosure, but due to the vagueness of the dispute, it is not clear whether the vendor is disputing this particular issue.