4
CVSSv2

CVE-2009-4467

Published: 30/12/2009 Updated: 17/08/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

misc.php in DeluxeBB 1.3 allows remote malicious users to register accounts without a valid email address via a valemail action with the valmem set to a pre-assigned user ID, which is visible from a memberlist action.

Vulnerable Product Search on Vulmon Subscribe to Product

deluxebb deluxebb 1.3

Exploits

# Author: cp77fk4r | Empty0pagE[Shift+2]gmailcom<gmailcom> # Vendor: wwwdeluxebbcom # #[Directory Listing] server/templates/ server/images/ server/logs/ server/wysiwyg/ server/docs/ server/classes server/lang server/settings/ # # #[Cross Site Scripting] server/mi ...