CVE-2006-7169 – Ultimate PHP Board 2.0 - 'header_simple.php' File Inclusion
https://notcve.org/view.php?id=CVE-2006-7169
PHP remote file inclusion vulnerability in includes/header_simple.php in Ultimate PHP Board (UPB) 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _CONFIG[skin_dir] parameter. Vulnerabilidad de inclusión remota de archivo en PHP en includes/header_simple.php de Ultimate PHP Board (UPB) 2.0 y anteriores permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro _CONFIG[skin_dir]. • https://www.exploit-db.com/exploits/2721 http://www.securityfocus.com/bid/20936 https://exchange.xforce.ibmcloud.com/vulnerabilities/30025 •
CVE-2006-6790 – Ultimate PHP Board 2.0b1 - '/chat/login.php' Code Execution
https://notcve.org/view.php?id=CVE-2006-6790
Direct static code injection vulnerability in chat/login.php in Ultimate PHP Board (UPB) 2.0b1 and earlier allows remote attackers to inject arbitrary PHP code via the username parameter, which is injected into chat/text.php. Vulnerabilidad de inyección directa de código estático en chat/login.php de Ultimate PHPBoard (UPB) 2.0b1 y anteriores permite a atacantes remotos inyectar código PHP de su elección a través del parámetro user, el cual es inyectado en chat/text.php. • https://www.exploit-db.com/exploits/2999 http://www.securityfocus.com/bid/21760 http://www.securityfocus.com/data/vulnerabilities/exploits/21760.pl http://www.vupen.com/english/advisories/2006/5181 •
CVE-2002-2322
https://notcve.org/view.php?id=CVE-2002-2322
Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords. • http://archives.neohapsis.com/archives/bugtraq/2002-10/0016.html http://www.iss.net/security_center/static/10300.php http://www.securityfocus.com/bid/5858 • CWE-20: Improper Input Validation •
CVE-2002-1821
https://notcve.org/view.php?id=CVE-2002-1821
Ultimate PHP Board (UPB) 1.0 and 1.0b allows remote authenticated users to gain privileges and perform unauthorized actions via direct requests to (1) admin_members.php, (2) admin_config.php, (3) admin_cat.php, or (4) admin_forum.php. • http://securitytracker.com/id?1005198 http://www.securityfocus.com/bid/5666 •
CVE-2002-1820
https://notcve.org/view.php?id=CVE-2002-1820
register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker to impersonate the administrator by registering an account name of admin with a lower case "a." • http://www.iss.net/security_center/static/9972.php http://www.securityfocus.com/archive/1/289417 http://www.securityfocus.com/bid/5580 • CWE-178: Improper Handling of Case Sensitivity •