« Volver al listado

CVE-2006-4080

Estado: ModificadaBaja (2.6)—

DeluxeBB 1.08, and possibly earlier, uses cookies that include the MD5 hash of a password, which allows remote attackers to gain privileges by sniffing or cross-site scripting (XSS) and conduct password guessing attacks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-4080",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.6,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-08-11T01:04:00.000",
  "references": [
    {
      "url": "http://securityreason.com/securityalert/1381",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/442464/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/1381",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/442464/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "DeluxeBB 1.08, and possibly earlier, uses cookies that include the MD5 hash of a password, which allows remote attackers to gain privileges by sniffing or cross-site scripting (XSS) and conduct password guessing attacks."
    },
    {
      "lang": "es",
      "value": "DeluxeBB 1.08, y posiblemente anteriores, usa cookies que incluyen el hash MD5 de una contraseña, lo cual permite a un atacante remoto escalar privilegios a través de sniffing o secuencias de comandos en sitios cruzados (XSS) y conducen la conrtaseña a ataques de conjetura."
    }
  ],
  "lastModified": "2026-06-16T22:28:23.330",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:deluxebb:deluxebb:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DFD476A9-7303-4020-BEC5-3714E0AB9E00",
              "versionEndIncluding": "1.08"
            },
            {
              "criteria": "cpe:2.3:a:deluxebb:deluxebb:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B3543354-4CC9-4C62-ACCE-6B646F797245"
            },
            {
              "criteria": "cpe:2.3:a:deluxebb:deluxebb:1.05:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9A65D83C-FB89-46C8-8ABA-D9F66ACE8B88"
            },
            {
              "criteria": "cpe:2.3:a:deluxebb:deluxebb:1.06:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37F38906-2E8F-40E4-A03B-8121FDEF903C"
            },
            {
              "criteria": "cpe:2.3:a:deluxebb:deluxebb:1.07:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC51CF33-9B6A-40BE-B5A6-3596C02C48B5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}