UBB.threads.Addpost.newpoll.PHP.Remote.File.Inclusion

description-logoDescription

PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute arbitrary PHP code via a URL in the thispath parameter.

affected-products-logoAffected Products

UBB.threads version 6.5.2 and prior.

Impact logoImpact

Execute arbitrary PHP code.

recomended-action-logoRecommended Actions

Upgrade to UBB.threads version 6.5.3 or later :

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)