Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to gain access via modified user_env, pass_env, power_env, and id_env parameters in a cookie, which comprise a persistent logon that does not vary across sessions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ultimate_php_board | Ultimate_php_board | 1.8 (including) | 1.8 (including) |
Ultimate_php_board | Ultimate_php_board | 1.8.2 (including) | 1.8.2 (including) |
Ultimate_php_board | Ultimate_php_board | 1.9 (including) | 1.9 (including) |
Ultimate_php_board | Ultimate_php_board | 1.9.6 (including) | 1.9.6 (including) |