your host has php running as a CGI ( there is a similar thread ) and the version of php they have installed is known to be vulnerable.

it isn't ubb software from what i can tell.

that is, IF you installed one of the xx.xx.xxp2 versions that are imperative.

2c