CVE Vulnerabilities

CVE-2006-4078

Published: Aug 11, 2006 | Modified: Oct 17, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

pm.php (aka the PM system) in DeluxeBB 1.08, and possibly earlier, allows remote attackers to bypass authentication by providing an arbitrary username in the membercookie cookie parameter.

Affected Software

Name Vendor Start Version End Version
Deluxebb Deluxebb 1.08 (including) 1.08 (including)

References