CVE-2006-3799

critical

Description

DeluxeBB 1.07 and earlier allows remote attackers to bypass SQL injection protection mechanisms via the login variable and certain other variables, by using lowercase "union select" or possibly other statements that do not match the uppercase "UNION SELECT."

References

http://www.vupen.com/english/advisories/2006/2879

http://www.securityfocus.com/archive/1/440435/100/0/threaded

http://securityreason.com/securityalert/1254

http://secunia.com/advisories/21116

http://lists.grok.org.uk/pipermail/full-disclosure/2006-July/047989.html

Details

Source: Mitre, NVD

Published: 2006-07-24

Updated: 2026-04-16

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.0036