CVE-2006-3799
Published Jul 24, 2006
Last updated 6 years ago
Overview
- Description
- DeluxeBB 1.07 and earlier allows remote attackers to bypass SQL injection protection mechanisms via the login variable and certain other variables, by using lowercase "union select" or possibly other statements that do not match the uppercase "UNION SELECT."
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:deluxebb:deluxebb:1.05:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9A65D83C-FB89-46C8-8ABA-D9F66ACE8B88" }, { "criteria": "cpe:2.3:a:deluxebb:deluxebb:1.06:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "37F38906-2E8F-40E4-A03B-8121FDEF903C" }, { "criteria": "cpe:2.3:a:deluxebb:deluxebb:1.07:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DC51CF33-9B6A-40BE-B5A6-3596C02C48B5" } ], "operator": "OR" } ] } ]