CVE-2006-3208
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Direct static code injection vulnerability in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote authenticated administrators to execute arbitrary PHP code via multiple unspecified "configuration fields" in (1) admin_chatconfig.php, (2) admin_configcss.php, (3) admin_config.php, or (4) admin_config2.php, which are stored as configuration settings. NOTE: this issue can be exploited by remote attackers by leveraging other vulnerabilities in UPB.
Vulnerabilidad de inyección directa de código estático en Ultimate PHP Board (UPB) v1.9.6 y anteriores permite a administradores autenticados remotamente ejecutar código PHP de su elección a através de múltiples "campos de comfiguración" sin especificar en (1) admin_chatconfig.php, (2) admin_configcss.php, (3) admin_config.php, o (4) admin_config2.php, que son almacenados como parámetros de configuración NOTA: este caso puede ser explotado por atacantes remotos aprovechando otras vulnerabilidades en UPB.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-06-23 CVE Reserved
- 2006-06-24 CVE Published
- 2024-02-28 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/1138 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/437875/100/0/threaded | Mailing List |
URL | Date | SRC |
---|---|---|
http://www.kliconsulting.com/users/mbrooks/UPB_0-day.txt | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ultimate Php Board Search vendor "Ultimate Php Board" | Ultimate Php Board Search vendor "Ultimate Php Board" for product "Ultimate Php Board" | 1.8 Search vendor "Ultimate Php Board" for product "Ultimate Php Board" and version "1.8" | - |
Affected
| ||||||
Ultimate Php Board Search vendor "Ultimate Php Board" | Ultimate Php Board Search vendor "Ultimate Php Board" for product "Ultimate Php Board" | 1.8.2 Search vendor "Ultimate Php Board" for product "Ultimate Php Board" and version "1.8.2" | - |
Affected
| ||||||
Ultimate Php Board Search vendor "Ultimate Php Board" | Ultimate Php Board Search vendor "Ultimate Php Board" for product "Ultimate Php Board" | 1.9 Search vendor "Ultimate Php Board" for product "Ultimate Php Board" and version "1.9" | - |
Affected
| ||||||
Ultimate Php Board Search vendor "Ultimate Php Board" | Ultimate Php Board Search vendor "Ultimate Php Board" for product "Ultimate Php Board" | 1.9.6 Search vendor "Ultimate Php Board" for product "Ultimate Php Board" and version "1.9.6" | - |
Affected
|