MEDIUM
Direct static code injection vulnerability in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote authenticated administrators to execute arbitrary PHP code via multiple unspecified "configuration fields" in (1) admin_chatconfig.php, (2) admin_configcss.php, (3) admin_config.php, or (4) admin_config2.php, which are stored as configuration settings
Published Jun 24, 2006
6.5
MEDIUMCVSS 2.0
EPSS 1.35%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.