7.5
CVSSv2

CVE-2006-4078

Published: 11/08/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

pm.php (aka the PM system) in DeluxeBB 1.08, and possibly earlier, allows remote malicious users to bypass authentication by providing an arbitrary username in the membercookie cookie parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

deluxebb deluxebb 1.08