CVE-2003-0395 – Ultimate PHP Board 1.9 - 'admin_iplog.php' Arbitrary PHP Execution
https://notcve.org/view.php?id=CVE-2003-0395
Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is executed when the administrator executes admin_iplog.php. Ultimate PHP Board (UPB) 1.9 permite a atacantes remotos ejecutar código PHP arbitrario con privilegios de administrador UPB mediante una petición HTTP conteniendo el código en la cabecera User-Agent, que es ejecutado cuando el administrador ejecuta admin_iplog.php. • https://www.exploit-db.com/exploits/22642 http://f0kp.iplus.ru/bz/024.en.txt http://marc.info/?l=bugtraq&m=105379741528925&w=2 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2002-2322
https://notcve.org/view.php?id=CVE-2002-2322
Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords. • http://archives.neohapsis.com/archives/bugtraq/2002-10/0016.html http://www.iss.net/security_center/static/10300.php http://www.securityfocus.com/bid/5858 • CWE-20: Improper Input Validation •
CVE-2002-1821
https://notcve.org/view.php?id=CVE-2002-1821
Ultimate PHP Board (UPB) 1.0 and 1.0b allows remote authenticated users to gain privileges and perform unauthorized actions via direct requests to (1) admin_members.php, (2) admin_config.php, (3) admin_cat.php, or (4) admin_forum.php. • http://securitytracker.com/id?1005198 http://www.securityfocus.com/bid/5666 •
CVE-2002-1820
https://notcve.org/view.php?id=CVE-2002-1820
register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker to impersonate the administrator by registering an account name of admin with a lower case "a." • http://www.iss.net/security_center/static/9972.php http://www.securityfocus.com/archive/1/289417 http://www.securityfocus.com/bid/5580 • CWE-178: Improper Handling of Case Sensitivity •
CVE-2002-2276
https://notcve.org/view.php?id=CVE-2002-2276
Ultimate PHP Board (UPB) 1.0 allows remote attackers to view the physical path of the message board via a direct request to add.php, which leaks the path in an error message. • http://archives.neohapsis.com/archives/bugtraq/2002-12/0071.html http://www.securityfocus.com/bid/6333 https://exchange.xforce.ibmcloud.com/vulnerabilities/10788 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •