CVE-2005-1615

viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 may allow remote attackers to read sensitive data via the postorder parameter, which is not properly handled by textdb.inc.php, possibly due to a SQL injection vulnerability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ultimate_php_board:ultimate_php_board:1.8:*:*:*:*:*:*:*
cpe:2.3:a:ultimate_php_board:ultimate_php_board:1.8.2:*:*:*:*:*:*:*
cpe:2.3:a:ultimate_php_board:ultimate_php_board:1.9:*:*:*:*:*:*:*
cpe:2.3:a:ultimate_php_board:ultimate_php_board:1.9.6:*:*:*:*:*:*:*

History

20 Nov 2024, 23:57

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=111600262424876&w=2 - () http://marc.info/?l=bugtraq&m=111600262424876&w=2 -
References () http://www.securityfocus.com/bid/13622 - () http://www.securityfocus.com/bid/13622 -

Information

Published : 2005-05-16 04:00

Updated : 2024-11-20 23:57


NVD link : CVE-2005-1615

Mitre link : CVE-2005-1615

CVE.ORG link : CVE-2005-1615


JSON object : View

Products Affected

ultimate_php_board

  • ultimate_php_board