CVE-2006-3796

DeluxeBB 1.07 and earlier does not properly handle a username composed of a single space character, which allows remote authenticated users to login as the "space" user, post as the guest user, and block the ability of an administrator to ban the "space" user.
Configurations

Configuration 1 (hide)

cpe:2.3:a:deluxebb:deluxebb:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:14

Type Values Removed Values Added
References () http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047989.html - () http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047989.html -
References () http://securityreason.com/securityalert/1254 - () http://securityreason.com/securityalert/1254 -
References () http://www.securityfocus.com/archive/1/440435/100/0/threaded - () http://www.securityfocus.com/archive/1/440435/100/0/threaded -
References () http://www.securityfocus.com/bid/19052 - () http://www.securityfocus.com/bid/19052 -

Information

Published : 2006-07-24 12:19

Updated : 2024-11-21 00:14


NVD link : CVE-2006-3796

Mitre link : CVE-2006-3796

CVE.ORG link : CVE-2006-3796


JSON object : View

Products Affected

deluxebb

  • deluxebb