// For flags

CVE-2006-3208

 

Severity Score

6.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Direct static code injection vulnerability in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote authenticated administrators to execute arbitrary PHP code via multiple unspecified "configuration fields" in (1) admin_chatconfig.php, (2) admin_configcss.php, (3) admin_config.php, or (4) admin_config2.php, which are stored as configuration settings. NOTE: this issue can be exploited by remote attackers by leveraging other vulnerabilities in UPB.

Vulnerabilidad de inyección directa de código estático en Ultimate PHP Board (UPB) v1.9.6 y anteriores permite a administradores autenticados remotamente ejecutar código PHP de su elección a através de múltiples "campos de comfiguración" sin especificar en (1) admin_chatconfig.php, (2) admin_configcss.php, (3) admin_config.php, o (4) admin_config2.php, que son almacenados como parámetros de configuración NOTA: este caso puede ser explotado por atacantes remotos aprovechando otras vulnerabilidades en UPB.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-06-23 CVE Reserved
  • 2006-06-24 CVE Published
  • 2024-02-28 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ultimate Php Board
Search vendor "Ultimate Php Board"
Ultimate Php Board
Search vendor "Ultimate Php Board" for product "Ultimate Php Board"
1.8
Search vendor "Ultimate Php Board" for product "Ultimate Php Board" and version "1.8"
-
Affected
Ultimate Php Board
Search vendor "Ultimate Php Board"
Ultimate Php Board
Search vendor "Ultimate Php Board" for product "Ultimate Php Board"
1.8.2
Search vendor "Ultimate Php Board" for product "Ultimate Php Board" and version "1.8.2"
-
Affected
Ultimate Php Board
Search vendor "Ultimate Php Board"
Ultimate Php Board
Search vendor "Ultimate Php Board" for product "Ultimate Php Board"
1.9
Search vendor "Ultimate Php Board" for product "Ultimate Php Board" and version "1.9"
-
Affected
Ultimate Php Board
Search vendor "Ultimate Php Board"
Ultimate Php Board
Search vendor "Ultimate Php Board" for product "Ultimate Php Board"
1.9.6
Search vendor "Ultimate Php Board" for product "Ultimate Php Board" and version "1.9.6"
-
Affected