NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 81227 | CVE-2002-2276 | Ultimate PHP Board (UPB) 1.0 allows remote attackers to view the physical path of the message board via a direct request to add.php, which leaks the path in an error message. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
| 80772 | CVE-2002-1821 | Ultimate PHP Board (UPB) 1.0 and 1.0b allows remote authenticated users to gain privileges and perform unauthorized actions via direct requests to (1) admin_members.php, (2) admin_config.php, (3) admin_cat.php, or (4) admin_forum.php. | 2 | 4.6 | Medium | 2017-01-05 | 2008-09-05 | View | |
| 81273 | CVE-2002-2322 | Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
| 73525 | CVE-2003-0395 | Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is executed when the administrator executes admin_iplog.php. | 2 | 7.5 | High | 2017-01-03 | 2016-10-17 | View | |
| 61884 | CVE-2006-3205 | Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to gain access via modified user_env, pass_env, power_env, and id_env parameters in a cookie, which comprise a persistent logon that does not vary across sessions. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View |
Page 15242 of 17672, showing 5 records out of 88360 total, starting on record 76206, ending on 76210