CVE-2005-1615 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.1% (pctl 81)
Patch early
A public exploit exists.
Description
viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 may allow remote attackers to read sensitive data via the postorder parameter, which is not properly handled by textdb.inc.php, possibly due to a SQL injection vulnerability.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.06% — more likely to be exploited than 81% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-05-16 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ultimate php board | ultimate php board |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Ultimate PHP Board 1.8/1.9 - 'viewforum.php' SQL Injection | 2005-05-13 |
References
→ the Explorer · watch your stack · NVD