CVE Vulnerabilities

CVE-2006-3798

Published: Jul 24, 2006 | Modified: Oct 17, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

DeluxeBB 1.07 and earlier allows remote attackers to overwrite the (1) _GET, (2) _POST, (3) _ENV, and (4) _SERVER variables via the _COOKIE (aka COOKIE) variable, which can overwrite the other variables during an extract function call, probably leading to multiple security vulnerabilities, aka pollution of the global namespace.

Affected Software

Name Vendor Start Version End Version
Deluxebb Deluxebb 1.05 (including) 1.05 (including)
Deluxebb Deluxebb 1.06 (including) 1.06 (including)
Deluxebb Deluxebb 1.07 (including) 1.07 (including)

References