CVE-2012-4036: Pbboard

Medium severity, CVSS 6.8. EPSS: 2.6% chance of exploitation in the next 30 days.

Unrestricted file upload vulnerability in admin.php in PBBoard 2.1.4 allows remote administrators to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in the addons directory. NOTE: this vulnerability can be leveraged by remote attackers using CVE-2012-1216.

Affected products

  • Pbboard Pbboard: version 2.1.4 only

Published 2012-08-27. Last modified 2026-06-16.