7.5
CVSSv2

CVE-2006-3799

Published: 24/07/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

DeluxeBB 1.07 and previous versions allows remote malicious users to bypass SQL injection protection mechanisms via the login variable and certain other variables, by using lowercase "union select" or possibly other statements that do not match the uppercase "UNION SELECT."

Vulnerable Product Search on Vulmon Subscribe to Product

deluxebb deluxebb 1.05

deluxebb deluxebb 1.06

deluxebb deluxebb 1.07