7.5
CVSSv2

CVE-2003-0395

Published: 02/07/2003 Updated: 13/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Ultimate PHP Board (UPB) 1.9 allows remote malicious users to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is executed when the administrator executes admin_iplog.php.

Vulnerable Product Search on Vulmon Subscribe to Product

myupb ultimate php board 1.9

Exploits

source: wwwsecurityfocuscom/bid/7678/info A vulnerability has been reported in Ultimate PHP Board The problem is said to occur due to insufficient sanitization of user-supplied input before including log data into a PHP file As a result, it may be possible for a remote attacker to execute arbitrary PHP commands within the context of the ...