PT-2005-2594 · Unknown · Ultimate Php Board

Morinex

·

Published

2005-05-16

·

Updated

2016-10-18

·

CVE-2005-1615

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ultimate PHP Board (UPB) versions 1.8 through 1.9.6
Description The issue allows remote attackers to read sensitive data. This is possibly due to a SQL injection vulnerability, where the postorder parameter is not properly handled by textdb.inc.php in viewforum.php.
Recommendations For Ultimate PHP Board (UPB) versions 1.8 through 1.9.6, consider restricting access to the viewforum.php page until a proper fix is applied, and avoid using the postorder parameter in this context to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1615

Affected Products

Ultimate Php Board