CVE-2006-2675

UBBThreads <6.x - RCE

Title source: llm

Description

PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote attackers to execute arbitrary PHP code via a URL in the (1) thispath or (2) configdir parameters.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/1843

Scores

EPSS 0.0168
EPSS Percentile 82.2%

Details

Status published
Products (27)
ubbcentral/ubb.threads 3.4
ubbcentral/ubb.threads 3.5
ubbcentral/ubb.threads 5.0
ubbcentral/ubb.threads 5.5.1
ubbcentral/ubb.threads 6.0
ubbcentral/ubb.threads 6.0.1
ubbcentral/ubb.threads 6.0.2
ubbcentral/ubb.threads 6.0.3
ubbcentral/ubb.threads 6.1
ubbcentral/ubb.threads 6.1.1
... and 17 more
Published May 30, 2006
Tracked Since Feb 18, 2026