← Vulnerability feed

Vulnerability record · CVE-2006-2568 · published 24 May 2006

CVE-2006-2568: Ubbcentral ubb.threads vulnerability

Ubbcentral · Ubb.Threads

PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute arbitrary PHP code via a URL in the thispath parameter.

5.1 CVSS 2.0 Medium EPSS 7.9% · top 5.5%
5.1CVSS 2.0 base score
7.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allows remote attackers to execute arbitrary PHP code via a URL in the thispath parameter.

AV:N/AC:H/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-2568 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2008-6970Ubbcentral ubb.threads sql injection vulnerabilitySQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Fo…EPSS 7.3%7.5CVE-2007-1956Ubbcentral ubb.threads vulnerabilitySQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via …EPSS 0.98%7.5CVE-2006-5136Ubbcentral ubb.threads vulnerabilityMultiple PHP remote file inclusion vulnerabilities in ubbt.inc.php in Groupee UBB.threads 6.5.1.1 allow remote attackers to execute arbitrary PHP cod…EPSS 1.6%7.5CVE-2006-0545Ubbcentral ubb.threads vulnerabilitySQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to execute arb…EPSS 1.3%7.5CVE-2005-2058Ubbcentral ubb.threads vulnerabilityMultiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Numb…EPSS 1.2%7.5CVE-2005-0726Ubbcentral ubb.threads vulnerabilitySQL injection vulnerability in editpost.php in UBB.threads 6.0 allows remote attackers to execute arbitrary SQL commands via the Number parameter.EPSS 1.2%7.5CVE-2004-1622Ubbcentral ubb.threads vulnerabilitySQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.EPSS 2.4%6.8CVE-2005-2057Ubbcentral ubb.threads vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2006-2568), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.