5.1
CVSSv2

CVE-2006-2675

Published: 30/05/2006 Updated: 18/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote malicious users to execute arbitrary PHP code via a URL in the (1) thispath or (2) configdir parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

ubbcentral ubb.threads 3.4

ubbcentral ubb.threads 3.5

ubbcentral ubb.threads 6.1

ubbcentral ubb.threads 6.1.1

ubbcentral ubb.threads 5.0

ubbcentral ubb.threads 5.5.1

ubbcentral ubb.threads 6.2

ubbcentral ubb.threads 6.2.1

ubbcentral ubb.threads 6.4.2

ubbcentral ubb.threads 6.4.3

ubbcentral ubb.threads 6.4.4

ubbcentral ubb.threads 6.4

ubbcentral ubb.threads 6.4.1

ubbcentral ubb.threads 6.5.2_beta2

ubbcentral ubb.threads

ubbcentral ubb.threads 6.0

ubbcentral ubb.threads 6.0.1

ubbcentral ubb.threads 6.2.2

ubbcentral ubb.threads 6.2.3

ubbcentral ubb.threads 6.5

ubbcentral ubb.threads 6.5.1

ubbcentral ubb.threads 6.0.2

ubbcentral ubb.threads 6.0.3

ubbcentral ubb.threads 6.3

ubbcentral ubb.threads 6.3.1

ubbcentral ubb.threads 6.5.1.1

ubbcentral ubb.threads 6.5.2

Exploits

UBBThreads 5x,6x Multiple File Inclusion Vulnerabilities Contacts > ICQ: 10072 MSN/Mail: nukedx@nukedxcom web: wwwnukedxcom This exploits works on UBBThreads 5x,6x Original advisory can be found at: wwwnukedxcom/?viewdoc=40 Succesful exploitation register_globals on Version 6x GET -> [site]/[ubbpath]/includepollresults ...