I don't think that can find any vulnerabilities - I see this alot of you're using Search Engine friendly URLs and any relative links. It's not SQL injection they are trying, it's just a URL.
The link can end up being
http://www.yourdomain.com/ubbthreads/ubbthreads.php/Cat/http://66.89.120.35If the URL on your site, ends up ending with a trailing slash, any other links can look relative. The jibberish at the end might be part of the session ID? If you're using the search engine URLs you'll see alot of this.