Ultimate PHP Board (UPB) 1.0 and 1.0b allows remote authenticated users to gain privileges and perform unauthorized actions via direct requests to (1) admin_members.php, (2) admin_config.php, (3) admin_cat.php, or (4) admin_forum.php.
Link | Tags |
---|---|
http://securitytracker.com/id?1005198 | vdb entry |
http://www.securityfocus.com/bid/5666 | vdb entry |