CVE Database
/

CVE-2006-5511

Back to search

CVE-2006-5511

Published: Oct 25, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Direct static code injection vulnerability in delete.php in JaxUltraBB (JUBB) 2.0, when register_globals is enabled, allows remote attackers to inject arbitrary web script, HTML, or PHP via the contents parameter, whose value is prepended to the file specified by the forum parameter.

VendorProductVersions

n/a

n/a

affected
n/a

References

20679
vdb-entry
x_refsource_BID
2616
exploit
x_refsource_EXPLOIT-DB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now