6.5
CVSSv2

CVE-2006-3208

Published: 24/06/2006 Updated: 14/02/2024
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Direct static code injection vulnerability in Ultimate PHP Board (UPB) 1.9.6 and previous versions allows remote authenticated administrators to execute arbitrary PHP code via multiple unspecified "configuration fields" in (1) admin_chatconfig.php, (2) admin_configcss.php, (3) admin_config.php, or (4) admin_config2.php, which are stored as configuration settings. NOTE: this issue can be exploited by remote attackers by leveraging other vulnerabilities in UPB.

Vulnerable Product Search on Vulmon Subscribe to Product

ultimate php board ultimate php board 1.9.6

ultimate php board ultimate php board 1.8

ultimate php board ultimate php board 1.8.2

ultimate php board ultimate php board 1.9