Back

CVE-2006-0214

Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the db_id parameter to visitorupload.php, as demonstrated using phpinfo and include function calls.

Published: Jan 15, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
indexcor ezdatabase 2.0
indexcor ezdatabase 2.1.2

GitHub Security Advisory GHSA-chcx-3744-px52

Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.87%

Top 14% most likely to be exploited

Threat Score 30.9 / 100

Data Sources

NVD EPSS GitHub