Vulnerabilities > CVE-2006-2915 - SQL Injection vulnerability in Deluxebb 1.06

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
deluxebb

Summary

Multiple SQL injection vulnerabilities in DeluxeBB 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) hideemail, (2) languagex, (3) xthetimeoffset, and (4) xthetimeformat parameters during account registration.

Vulnerable Configurations

Part Description Count
Application
Deluxebb
1

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/47543/secunia-deluxebb.txt
idPACKETSTORM:47543
last seen2016-12-05
published2006-06-21
reporterAndreas Sandblad
sourcehttps://packetstormsecurity.com/files/47543/secunia-deluxebb.txt.html
titlesecunia-deluxebb.txt