Security Advisory
CVE-2006-3206
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
register.php in Ultimate PHP Board (UPB) 1.9.6 and earlier allows remote attackers to create arbitrary accounts via the "[NR]" sequence in the signature field, which is used to separate multiple records.