PT-2010-3485 · Deluxebb · Deluxebb
Published
2010-05-07
·
Updated
2010-05-10
·
CVE-2010-1859
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
DeluxeBB versions 1.3 and earlier
Description
The issue allows remote attackers to execute arbitrary SQL commands via the
membercookie cookie when adding a new thread, specifically in the newpost.php file, when magic quotes gpc is disabled.Recommendations
For DeluxeBB versions 1.3 and earlier, consider disabling the use of the
membercookie cookie or restrict access to the newpost.php file until a patch is available. Additionally, enabling magic quotes gpc may help mitigate the risk of exploitation.Exploit
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Deluxebb