← Vulnerability feed

Vulnerability record · CVE-2008-6970 · published 13 August 2009

CVE-2008-6970: Ubbcentral ubb.threads sql injection vulnerability

Ubbcentral · Ubb.Threads

SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Forum[] array parameter.

7.5 CVSS 2.0 High EPSS 7.3% · top 5.9% CWE-89 · SQL injection
7.5CVSS 2.0 base score
7.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the Forum[] array parameter.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-6970 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2007-1956Ubbcentral ubb.threads vulnerabilitySQL injection vulnerability in ubbthreads.php in Groupee UBB.threads 6.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via …EPSS 0.98%7.5CVE-2006-5136Ubbcentral ubb.threads vulnerabilityMultiple PHP remote file inclusion vulnerabilities in ubbt.inc.php in Groupee UBB.threads 6.5.1.1 allow remote attackers to execute arbitrary PHP cod…EPSS 1.6%7.5CVE-2006-0545Ubbcentral ubb.threads vulnerabilitySQL injection vulnerability in showflat.php in Groupee (formerly known as Infopop) UBB.threads 6.3 and earlier allows remote attackers to execute arb…EPSS 1.3%7.5CVE-2005-2058Ubbcentral ubb.threads vulnerabilityMultiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Numb…EPSS 1.2%7.5CVE-2005-0726Ubbcentral ubb.threads vulnerabilitySQL injection vulnerability in editpost.php in UBB.threads 6.0 allows remote attackers to execute arbitrary SQL commands via the Number parameter.EPSS 1.2%7.5CVE-2004-1622Ubbcentral ubb.threads vulnerabilitySQL injection vulnerability in dosearch.php in UBB.threads 3.4.x allows remote attackers to execute arbitrary SQL statements via the Name parameter.EPSS 2.4%6.8CVE-2005-2057Ubbcentral ubb.threads vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or…EPSS 1.5%6.5CVE-2005-2059Ubbcentral ubb.threads cross-site request forgery vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.p…EPSS 0.96%

Source: NIST National Vulnerability Database (record CVE-2008-6970), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.