A vulnerability has been identified in Ultimate PHP Board (UPB), which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This issue is caused by input and access validation errors in the "admin_restore.php" script when processing the "file" parameter while "action" is set to "download", which could be exploited to download arbitrary files via directory traversal attacks.
Vulnerable Products
Vulnerable Software: Ultimate PHP Board (UPB) version 2.2.6 and prior