SQL injection vulnerability in DeluxeBB 1.07 and earlier allows remote attackers to bypass authentication, spoof users, and modify settings via the (1) memberpw and (2) membercookie cookies.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Deluxebb | Deluxebb | 1.05 (including) | 1.05 (including) |
Deluxebb | Deluxebb | 1.06 (including) | 1.06 (including) |
Deluxebb | Deluxebb | 1.07 (including) | 1.07 (including) |