« Volver al listado

CVE-2006-3205

Estado: ModificadaMedia (5)—

Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to gain access via modified user_env, pass_env, power_env, and id_env parameters in a cookie, which comprise a persistent logon that does not vary across sessions.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-3205",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-06-24T01:06:00.000",
  "references": [
    {
      "url": "http://securityreason.com/securityalert/1138",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.kliconsulting.com/users/mbrooks/UPB_0-day.txt",
      "tags": [
        "URL Repurposed"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/437875/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/1138",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kliconsulting.com/users/mbrooks/UPB_0-day.txt",
      "tags": [
        "URL Repurposed"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/437875/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to gain access via modified user_env, pass_env, power_env, and id_env parameters in a cookie, which comprise a persistent logon that does not vary across sessions."
    },
    {
      "lang": "es",
      "value": "Ultimate PHP Board (UPB) v1.9.6 y anteriores permite a atacantes remotos obtener acceso a através de los parámetros modificados user_env, pass_env, power_env, y id_env en una cookie, que comprenden un inicio de sesión persistente que no varía en los diferentes períodos de sesiones."
    }
  ],
  "lastModified": "2026-06-16T22:26:37.290",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ultimate_php_board:ultimate_php_board:1.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8EC70A25-AB74-4088-BB10-3B7748E70EA0"
            },
            {
              "criteria": "cpe:2.3:a:ultimate_php_board:ultimate_php_board:1.8.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53E41185-4834-4D85-AF2D-7F10AA98481D"
            },
            {
              "criteria": "cpe:2.3:a:ultimate_php_board:ultimate_php_board:1.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76565865-21E3-4007-8624-48FDC000EBF3"
            },
            {
              "criteria": "cpe:2.3:a:ultimate_php_board:ultimate_php_board:1.9.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7869B748-3898-44CA-BA28-B81491241043"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}