PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute arbitrary PHP code via a URL in the thispath parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ubb.threads | Ubbcentral | 6.4 (including) | 6.4 (including) |
Ubb.threads | Ubbcentral | 6.4.1 (including) | 6.4.1 (including) |
Ubb.threads | Ubbcentral | 6.4.2 (including) | 6.4.2 (including) |
Ubb.threads | Ubbcentral | 6.4.3 (including) | 6.4.3 (including) |
Ubb.threads | Ubbcentral | 6.4.4 (including) | 6.4.4 (including) |
Ubb.threads | Ubbcentral | 6.5 (including) | 6.5 (including) |
Ubb.threads | Ubbcentral | 6.5.1 (including) | 6.5.1 (including) |
Ubb.threads | Ubbcentral | 6.5.1.1 (including) | 6.5.1.1 (including) |
Ubb.threads | Ubbcentral | 6.5.2 (including) | 6.5.2 (including) |