Vulnerabilities > Deluxebb > Low

DATE CVE VULNERABILITY TITLE RISK
2006-08-11 CVE-2006-4080 Cross-Site Scripting vulnerability in DeluxeBB
DeluxeBB 1.08, and possibly earlier, uses cookies that include the MD5 hash of a password, which allows remote attackers to gain privileges by sniffing or cross-site scripting (XSS) and conduct password guessing attacks.
network
high complexity
deluxebb
2.6
2006-07-24 CVE-2006-3795 Input Validation vulnerability in DeluxeBB
Multiple cross-site scripting (XSS) vulnerabilities in DeluxeBB before 1.08 allow remote attackers to inject arbitrary web script or HTML via the (1) membercookie cookie in header.php and the (2) redirect parameter in misc.php.
network
high complexity
deluxebb
2.6