CVE-2005-2058

UBB.Threads - SQL Injection via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 8 public exploits for CVE-2005-2058. PoCs published by mh_p0rtal, GulfTech Security.

AI-analyzed exploit summary This PHP script exploits a SQL injection vulnerability in UBBCentral by injecting a UNION-based query to extract user credentials. It sends a crafted HTTP GET request to the vulnerable endpoint to retrieve the username and password of a specified user.

Description

Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to calendar.php, (7) message parameter to viewmessage.php, (8) main parameter to addfav.php, or (9) posted parameter to grabnext.php.

Exploits (8)

exploitdb WORKING POC VERIFIED
by mh_p0rtal · phpwebappsphp
https://www.exploit-db.com/exploits/1069

This PHP script exploits a SQL injection vulnerability in UBBCentral by injecting a UNION-based query to extract user credentials. It sends a crafted HTTP GET request to the vulnerable endpoint to retrieve the username and password of a specified user.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: UBBCentral (version not specified)
No auth needed
Prerequisites: Target URL and directory path of the vulnerable UBBCentral installation
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/25900

This exploit demonstrates a SQL injection vulnerability in UBB.Threads by injecting a UNION-based query to extract user credentials from the database. The attack leverages unsanitized input in the 'message' parameter to manipulate the SQL query.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: UBB.Threads
No auth needed
Prerequisites: Access to the vulnerable UBB.Threads instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/25902

The provided text describes a SQL injection vulnerability in UBB.Threads, where the 'Number' parameter in the 'notifymod.php' script is vulnerable due to insufficient input sanitization. The example URL demonstrates how an attacker could inject malicious SQL queries.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: UBB.Threads
No auth needed
Prerequisites: Access to the vulnerable UBB.Threads instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/25899

The provided text describes a SQL injection vulnerability in UBB.Threads, detailing a vulnerable URL parameter. It does not contain executable exploit code but explains the vulnerability and potential impact.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: UBB.Threads
No auth needed
Prerequisites: Access to the vulnerable UBB.Threads application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/25903

The provided text describes a SQL injection vulnerability in UBB.Threads, where the application fails to sanitize user input in the 'grabnext.php' script. The example URL demonstrates how an attacker could inject malicious SQL queries via the 'posted' parameter.

Classification
Writeup 80%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: UBB.Threads
No auth needed
Prerequisites: Access to the vulnerable UBB.Threads instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/25897

The provided text describes a SQL injection vulnerability in UBB.Threads, where the 'Number' parameter in download.php is not properly sanitized. It includes a sample exploit URL but lacks executable code.

Classification
Writeup 80%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: UBB.Threads
No auth needed
Prerequisites: Access to the vulnerable UBB.Threads instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/25898

The provided text describes SQL injection vulnerabilities in UBB.Threads, specifically in the calendar.php file, where user-supplied input is not properly sanitized. It includes example URLs demonstrating the vulnerability but lacks executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: UBB.Threads
No auth needed
Prerequisites: Access to the vulnerable UBB.Threads application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by GulfTech Security · textwebappsphp
https://www.exploit-db.com/exploits/25901

The provided text describes a SQL injection vulnerability in UBB.Threads, where the 'main' parameter in the URL is not properly sanitized, allowing attackers to inject malicious SQL queries. The example URL demonstrates how an attacker could exploit this vulnerability to manipulate the database.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: UBB.Threads
No auth needed
Prerequisites: Access to the vulnerable UBB.Threads application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Patch, Vendor Advisory x_refsource_misc
http://www.gulftech.org/?node=research&article_id=00084-06232005
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111963737202040&w=2

Scores

EPSS 0.0124
EPSS Percentile 65.1%

Details

Status published
Products (20)
ubbcentral/ubb.threads 6.0
ubbcentral/ubb.threads 6.0.1
ubbcentral/ubb.threads 6.0.2
ubbcentral/ubb.threads 6.0.3
ubbcentral/ubb.threads 6.1
ubbcentral/ubb.threads 6.1.1
ubbcentral/ubb.threads 6.2
ubbcentral/ubb.threads 6.2.1
ubbcentral/ubb.threads 6.2.2
ubbcentral/ubb.threads 6.2.3
... and 10 more
Published Jun 29, 2005
Tracked Since Feb 18, 2026