Vulnerabilities > CVE-2006-3799 - Input Validation vulnerability in Deluxebb 1.05/1.06/1.07
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
DeluxeBB 1.07 and earlier allows remote attackers to bypass SQL injection protection mechanisms via the login variable and certain other variables, by using lowercase "union select" or possibly other statements that do not match the uppercase "UNION SELECT."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047989.html
- http://secunia.com/advisories/21116
- http://securityreason.com/securityalert/1254
- http://www.securityfocus.com/archive/1/440435/100/0/threaded
- http://www.securityfocus.com/bid/19052
- http://www.vupen.com/english/advisories/2006/2879