VYPR
Unrated severityNVD Advisory· Published Jul 24, 2006· Updated Apr 16, 2026

CVE-2006-3797

CVE-2006-3797

Description

SQL injection vulnerability in DeluxeBB 1.07 and earlier allows remote attackers to bypass authentication, spoof users, and modify settings via the (1) memberpw and (2) membercookie cookies.

Affected products

3
  • Deluxebb/Deluxebb3 versions
    cpe:2.3:a:deluxebb:deluxebb:1.05:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:deluxebb:deluxebb:1.05:*:*:*:*:*:*:*
    • cpe:2.3:a:deluxebb:deluxebb:1.06:*:*:*:*:*:*:*
    • cpe:2.3:a:deluxebb:deluxebb:1.07:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.