CVE-2006-3204
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Ultimate PHP Board (UPB) 1.9.6 and earlier uses a cryptographically weak block cipher with a large key collision space, which allows remote attackers to determine a suitable decryption key given the plaintext and ciphertext by obtaining the plaintext password, which is sent when logging in, and the ciphertext, which is set in the pass_env cookie.
Ultimate PHP Board (UPB) v1.9.6 y anteriores usa un bloque de cifrado criptográficamente débil con un gran espacio de llaves de colisiones, lo que permite a atacantes remotos determinar una llave de descripción apropiada dando el texto plano y el texto cifrado mediante la obtención de la contraseña de texto plano, que es enviado cuando se loguea, y el texto cifrado, cuando es establecido en la cookie pass_env.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-06-23 CVE Reserved
- 2006-06-24 CVE Published
- 2024-02-28 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/1138 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/437875/100/0/threaded | Mailing List |
URL | Date | SRC |
---|---|---|
http://www.kliconsulting.com/users/mbrooks/UPB_0-day.txt | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ultimate Php Board Search vendor "Ultimate Php Board" | Ultimate Php Board Search vendor "Ultimate Php Board" for product "Ultimate Php Board" | 1.8 Search vendor "Ultimate Php Board" for product "Ultimate Php Board" and version "1.8" | - |
Affected
| ||||||
Ultimate Php Board Search vendor "Ultimate Php Board" | Ultimate Php Board Search vendor "Ultimate Php Board" for product "Ultimate Php Board" | 1.8.2 Search vendor "Ultimate Php Board" for product "Ultimate Php Board" and version "1.8.2" | - |
Affected
| ||||||
Ultimate Php Board Search vendor "Ultimate Php Board" | Ultimate Php Board Search vendor "Ultimate Php Board" for product "Ultimate Php Board" | 1.9 Search vendor "Ultimate Php Board" for product "Ultimate Php Board" and version "1.9" | - |
Affected
| ||||||
Ultimate Php Board Search vendor "Ultimate Php Board" | Ultimate Php Board Search vendor "Ultimate Php Board" for product "Ultimate Php Board" | 1.9.6 Search vendor "Ultimate Php Board" for product "Ultimate Php Board" and version "1.9.6" | - |
Affected
|