Back

CVE-2005-1615

viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 may allow remote attackers to read sensitive data via the postorder parameter, which is not properly handled by textdb.inc.php, possibly due to a SQL injection vulnerability.

Published: May 16, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (4)

Vendor Product Version
ultimate_php_board ultimate_php_board 1.8
ultimate_php_board ultimate_php_board 1.8.2
ultimate_php_board ultimate_php_board 1.9
ultimate_php_board ultimate_php_board 1.9.6

GitHub Security Advisory GHSA-6vvx-rv64-v2x4

viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 may allow remote attackers to read...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.06%

Top 20% most likely to be exploited

Threat Score 30.6 / 100

Data Sources

NVD EPSS GitHub