NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
81227  CVE-2002-2276  Ultimate PHP Board (UPB) 1.0 allows remote attackers to view the physical path of the message board via a direct request to add.php, which leaks the path in an error message.    Medium  2017-01-05  2008-09-05  View
80772  CVE-2002-1821  Ultimate PHP Board (UPB) 1.0 and 1.0b allows remote authenticated users to gain privileges and perform unauthorized actions via direct requests to (1) admin_members.php, (2) admin_config.php, (3) admin_cat.php, or (4) admin_forum.php.    4.6  Medium  2017-01-05  2008-09-05  View
81273  CVE-2002-2322  Ultimate PHP Board (UPB) 1.0b stores the users.dat data file under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords.    Medium  2017-01-05  2008-09-05  View
73525  CVE-2003-0395  Ultimate PHP Board (UPB) 1.9 allows remote attackers to execute arbitrary PHP code with UPB administrator privileges via an HTTP request containing the code in the User-Agent header, which is executed when the administrator executes admin_iplog.php.    7.5  High  2017-01-03  2016-10-17  View
61884  CVE-2006-3205  Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to gain access via modified user_env, pass_env, power_env, and id_env parameters in a cookie, which comprise a persistent logon that does not vary across sessions.    Medium  2016-12-20  2008-09-05  View

Page 15242 of 17672, showing 5 records out of 88360 total, starting on record 76206, ending on 76210

Actions