Ultimate Php Board

Ultimate Php Board

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 16.10.2025 00:00:00
  • Zuletzt bearbeitet 21.10.2025 12:12:14

SQL injection vulnerability in Ultimate PHP Board 2.2.7 via the username field in lostpassword.php.

  • EPSS 0.03%
  • Veröffentlicht 16.10.2025 00:00:00
  • Zuletzt bearbeitet 21.10.2025 12:12:05

Cross site scripting (XSS) vulnerability in Ultimate PHP Board 2.2.7 via the u_name parameter in lostpassword.php.

  • EPSS 6.76%
  • Veröffentlicht 20.03.2007 10:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

PHP remote file inclusion vulnerability in includes/header_simple.php in Ultimate PHP Board (UPB) 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _CONFIG[skin_dir] parameter.

  • EPSS 3.36%
  • Veröffentlicht 28.12.2006 00:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Direct static code injection vulnerability in chat/login.php in Ultimate PHP Board (UPB) 2.0b1 and earlier allows remote attackers to inject arbitrary PHP code via the username parameter, which is injected into chat/text.php.

Exploit
  • EPSS 1.25%
  • Veröffentlicht 24.06.2006 01:06:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The installation of Ultimate PHP Board (UPB) 1.9.6 and earlier includes a default administrator login account and password, which allows remote attackers to gain privileges.

Exploit
  • EPSS 0.73%
  • Veröffentlicht 24.06.2006 01:06:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Direct static code injection vulnerability in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote authenticated administrators to execute arbitrary PHP code via multiple unspecified "configuration fields" in (1) admin_chatconfig.php, (2) admin_c...

  • EPSS 0.28%
  • Veröffentlicht 24.06.2006 01:06:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Directory traversal vulnerability in newpost.php in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the id parameter, as demonstrated by injec...

  • EPSS 0.34%
  • Veröffentlicht 24.06.2006 01:06:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

register.php in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to create arbitrary accounts via the "[NR]" sequence in the signature field, which is used to separate multiple records.

  • EPSS 0.39%
  • Veröffentlicht 24.06.2006 01:06:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to gain access via modified user_env, pass_env, power_env, and id_env parameters in a cookie, which comprise a persistent logon that does not vary across sessions.

Exploit
  • EPSS 0.46%
  • Veröffentlicht 24.06.2006 01:06:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Ultimate PHP Board (UPB) 1.9.6 and earlier uses a cryptographically weak block cipher with a large key collision space, which allows remote attackers to determine a suitable decryption key given the plaintext and ciphertext by obtaining the plaintext...