CVE-2006-5511
JaxUltraBB 2.0 - Code Injection
Title source: llmDescription
Direct static code injection vulnerability in delete.php in JaxUltraBB (JUBB) 2.0, when register_globals is enabled, allows remote attackers to inject arbitrary web script, HTML, or PHP via the contents parameter, whose value is prepended to the file specified by the forum parameter.
Exploits (1)
Scores
EPSS
0.0386
EPSS Percentile
88.2%
Details
Status
published
Products (1)
jaxultrabb/jaxultrabb
2.0
Published
Oct 25, 2006
Tracked Since
Feb 18, 2026