CVE-2006-1278
SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the libs directory, (3) edit.php and (4) delete.php in control/files/, (5) edit.php and (6) delete.php in control/users/, (7) edit.php, (8) access.php, and (9) in control/folders/, (10) access.php and (11) delete.php in control/groups/, (12) confirm.php, and (13) download.php; (14) the email parameter in password.php, and (15) the id parameter in folder.php. NOTE: it was later reported that vectors 12 and 13 also affect @1 File Store PRO 3.2.
CVSS
- Version: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
- Base score: 6.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 3.74%
- Percentile among all scored CVEs: 90
- Score date: 10/10/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · File Store PRO 3.2 - Multiple Blind SQL Injections (7/11/2008)
Affected technologies (1)
CWEs
- CWE-89
References
- http://evuln.com/vulns/95/summary.html
- http://osvdb.org/47017
- http://osvdb.org/47018
- http://secunia.com/advisories/19224
- http://secunia.com/advisories/31063
- http://securityreason.com/securityalert/619
- http://securitytracker.com/id?1015826
- http://www.attrition.org/pipermail/vim/2009-August/002246.html
- http://www.osvdb.org/23851
- http://www.osvdb.org/23852
- http://www.osvdb.org/23853
- http://www.osvdb.org/23854
- http://www.osvdb.org/23855
- http://www.osvdb.org/23856
- http://www.osvdb.org/23857
- http://www.osvdb.org/23858
- http://www.osvdb.org/23859
- http://www.osvdb.org/23860
- http://www.osvdb.org/23861
- http://www.osvdb.org/23862
- http://www.osvdb.org/23863
- http://www.osvdb.org/23864
- http://www.osvdb.org/24106
- http://www.securityfocus.com/archive/1/428659/100/0/threaded
- http://www.securityfocus.com/bid/17090
- http://www.securityfocus.com/bid/30182
- http://www.vupen.com/english/advisories/2006/0943
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25183
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43718
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43724
- https://www.exploit-db.com/exploits/6040
- http://evuln.com/vulns/95/summary.html
- http://osvdb.org/47017
- http://osvdb.org/47018
- http://secunia.com/advisories/19224
- http://secunia.com/advisories/31063
- http://securityreason.com/securityalert/619
- http://securitytracker.com/id?1015826
- http://www.attrition.org/pipermail/vim/2009-August/002246.html
- http://www.osvdb.org/23851
- http://www.osvdb.org/23852
- http://www.osvdb.org/23853
- http://www.osvdb.org/23854
- http://www.osvdb.org/23855
- http://www.osvdb.org/23856
- http://www.osvdb.org/23857
- http://www.osvdb.org/23858
- http://www.osvdb.org/23859
- http://www.osvdb.org/23860
- http://www.osvdb.org/23861
- http://www.osvdb.org/23862
- http://www.osvdb.org/23863
- http://www.osvdb.org/23864
- http://www.osvdb.org/24106
- http://www.securityfocus.com/archive/1/428659/100/0/threaded
- http://www.securityfocus.com/bid/17090
- http://www.securityfocus.com/bid/30182
- http://www.vupen.com/english/advisories/2006/0943
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25183
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43718
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43724
- https://www.exploit-db.com/exploits/6040
Raw JSON (NVD)
Show
{
"id": "CVE-2006-1278",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-03-19T11:06:00.000",
"references": [
{
"url": "http://evuln.com/vulns/95/summary.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/47017",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/47018",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/19224",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/31063",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/619",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1015826",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.attrition.org/pipermail/vim/2009-August/002246.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/23851",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/23852",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/23853",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/23854",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/23855",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/23856",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/23857",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/23858",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/23859",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/23860",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/23861",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/23862",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/23863",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/23864",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/24106",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/428659/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/17090",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/30182",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/0943",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/25183",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43718",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43724",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/6040",
"source": "cve@mitre.org"
},
{
"url": "http://evuln.com/vulns/95/summary.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/47017",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/47018",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/19224",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/31063",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/619",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1015826",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.attrition.org/pipermail/vim/2009-August/002246.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/23851",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/23852",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/23853",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/23854",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/23855",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/23856",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/23857",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/23858",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/23859",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/23860",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/23861",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/23862",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/23863",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/23864",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/24106",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/428659/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/17090",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/30182",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/0943",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/25183",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43718",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/43724",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/6040",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) functions.php and (2) user.php in the libs directory, (3) edit.php and (4) delete.php in control/files/, (5) edit.php and (6) delete.php in control/users/, (7) edit.php, (8) access.php, and (9) in control/folders/, (10) access.php and (11) delete.php in control/groups/, (12) confirm.php, and (13) download.php; (14) the email parameter in password.php, and (15) the id parameter in folder.php. NOTE: it was later reported that vectors 12 and 13 also affect @1 File Store PRO 3.2."
}
],
"lastModified": "2026-06-16T22:22:21.527",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:upoint:\\@1_file_store:2006.03.07:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C20CC9D0-7695-42A4-90C2-E1D5BC8B4FC0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org",
"evaluatorSolution": "Successful exploitation requires that the \"magic_quotes_gpc\" parameter is disabled."
}