← Back

CVE-2006-3798

nvd nist
Published: Jul 24, 2006Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

DeluxeBB 1.07 and earlier allows remote attackers to overwrite the (1) _GET, (2) _POST, (3) _ENV, and (4) _SERVER variables via the _COOKIE (aka COOKIE) variable, which can overwrite the other variables during an extract function call, probably leading to multiple security vulnerabilities, aka "pollution of the global namespace."

Affected (3)

Products: Deluxebb: Deluxebb
1 product
Deluxebb
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Deluxebb
Version 1.05
Version 1.06
Version 1.07

Timeline

No history available yet.