Well, there really are no known security exploits in current ubb.threads code - that's not saying someone hasn't found one tho. First option is to upgrade code to current released code. If you are unable to from your remote location I can do it for you very reasonably. PM me access details and I'll handle it today.
Outside the forum code itself - it really could be anything - if you recently upgraded from an older 6.5 series you could still have shell scripts on your server from the openings back then (prior to v 6.5.5). If there are any other scripts on your server they could be allowing access - anything else installed?
It could be the server software itself - are you running current software? (I would not run on anything less than current generally available versions on my own web sites).