Loading...
Loading...
Direct static code injection vulnerability in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote authenticated administrators to execute arbitrary PHP code via multiple unspecified "configuration fields" in (1) admin_chatconfig.php, (2) admin_configcss.php, (3) admin_config.php, or (4) admin_config2.php, which are stored as configuration settings. NOTE: this issue can be exploited by remote attackers by leveraging other vulnerabilities in UPB.
June 24, 2006
April 16, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2006-3208
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.