Total vulnerabilities in the database
register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker to impersonate the administrator by registering an account name of admin with a lower case "a."
Software | From | Fixed in |
---|---|---|
ultimate_php_board_project / ultimate_php_board | 1.0 | 1.0.x |
ultimate_php_board_project / ultimate_php_board | 1.0-beta | 1.0-beta.x |