Yep, caught me again. The check was too simplistic. I've updated it once again, this time it should catch the problem.
While I was at it, I also closed off another couple of potential holes, where users might have been able to use special shell characters (such as | or >) to do funny stuff.
I didn't bother making this a new version, so if you re-download 3.3, you'll get this fix.
As for omegatron's comment about the security hole being fixable by good permissions, I'd rather have the script do the right thing, as opposed to making the user worry about yet another problem.
Anyway, thanks for pointing out the hole, and keep the feedback coming! (Yeah, even the negative stuff :))
Donate to UBBDev today to help aid in Operational, Server and Script Maintenance, and Development costs.
Please also see our parent organization VNC Web Services if you're in the need of a new UBB.threads Install or Upgrade, Site/Server Migrations, or Security and Coding Services.