5
CVSSv2

CVE-2006-3798

Published: 24/07/2006 Updated: 17/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

DeluxeBB 1.07 and previous versions allows remote malicious users to overwrite the (1) _GET, (2) _POST, (3) _ENV, and (4) _SERVER variables via the _COOKIE (aka COOKIE) variable, which can overwrite the other variables during an extract function call, probably leading to multiple security vulnerabilities, aka "pollution of the global namespace."

Vulnerable Product Search on Vulmon Subscribe to Product

deluxebb deluxebb 1.06

deluxebb deluxebb 1.07

deluxebb deluxebb 1.05