SQL injection vulnerability in DeluxeBB 1.07 and earlier allows remote attackers to bypass authentication, spoof users, and modify settings via the (1) memberpw and (2) membercookie cookies.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Deluxebb | Deluxebb | 1.05 (including) | 1.05 (including) |
| Deluxebb | Deluxebb | 1.06 (including) | 1.06 (including) |
| Deluxebb | Deluxebb | 1.07 (including) | 1.07 (including) |