CVE-2002-1820 Information

Description

register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital \A\ but allows a remote attacker to impersonate the administrator by registering an account name of admin with a lower case \a.\

Reference

http://www.iss.net/security_center/static/9972.php http://www.securityfocus.com/archive/1/289417 http://www.securityfocus.com/bid/5580

Share on: