CVE Vulnerabilities

CVE-2005-1615

Published: May 16, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 may allow remote attackers to read sensitive data via the postorder parameter, which is not properly handled by textdb.inc.php, possibly due to a SQL injection vulnerability.

Affected Software

NameVendorStart VersionEnd Version
Ultimate_php_boardUltimate_php_board1.8 (including)1.8 (including)
Ultimate_php_boardUltimate_php_board1.8.2 (including)1.8.2 (including)
Ultimate_php_boardUltimate_php_board1.9 (including)1.9 (including)
Ultimate_php_boardUltimate_php_board1.9.6 (including)1.9.6 (including)

References