PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote attackers to execute arbitrary PHP code via a URL in the (1) thispath or (2) configdir parameters. Successful exploitation requires that "register_globals" is enabled.
Publication date: Wed, 31 May 2006 02:02:00 +0000