CVE-2025-61540
- EPSS 0.03%
- Veröffentlicht 16.10.2025 00:00:00
- Zuletzt bearbeitet 21.10.2025 12:12:14
SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php.
CVE-2025-61539
- EPSS 0.03%
- Veröffentlicht 16.10.2025 00:00:00
- Zuletzt bearbeitet 21.10.2025 12:12:05
Cross site scripting (XSS) vulnerability in Ultimate PHP Board 2.2.7 via the u_name parameter in lostpassword.php.
CVE-2006-7169
- EPSS 6.76%
- Veröffentlicht 20.03.2007 10:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PHP remote file inclusion vulnerability in includes/header_simple.php in Ultimate PHP Board (UPB) 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _CONFIG[skin_dir] parameter.
CVE-2006-6790
- EPSS 3.36%
- Veröffentlicht 28.12.2006 00:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Direct static code injection vulnerability in chat/login.php in Ultimate PHP Board (UPB) 2.0b1 and earlier allows remote attackers to inject arbitrary PHP code via the username parameter, which is injected into chat/text.php.
- EPSS 1.25%
- Veröffentlicht 24.06.2006 01:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The installation of Ultimate PHP Board (UPB) 1.9.6 and earlier includes a default administrator login account and password, which allows remote attackers to gain privileges.
CVE-2006-3208
- EPSS 0.73%
- Veröffentlicht 24.06.2006 01:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Direct static code injection vulnerability in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote authenticated administrators to execute arbitrary PHP code via multiple unspecified "configuration fields" in (1) admin_chatconfig.php, (2) admin_c...
- EPSS 0.28%
- Veröffentlicht 24.06.2006 01:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Directory traversal vulnerability in newpost.php in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the id parameter, as demonstrated by injec...
- EPSS 0.34%
- Veröffentlicht 24.06.2006 01:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
register.php in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to create arbitrary accounts via the "[NR]" sequence in the signature field, which is used to separate multiple records.
- EPSS 0.39%
- Veröffentlicht 24.06.2006 01:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to gain access via modified user_env, pass_env, power_env, and id_env parameters in a cookie, which comprise a persistent logon that does not vary across sessions.
- EPSS 0.46%
- Veröffentlicht 24.06.2006 01:06:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Ultimate PHP Board (UPB) 1.9.6 and earlier uses a cryptographically weak block cipher with a large key collision space, which allows remote attackers to determine a suitable decryption key given the plaintext and ciphertext by obtaining the plaintext...