CVE-2007-6237 describes a critical vulnerability in DeluxeBB 1.09 where the cp.php script fails to validate the membercookie parameter during profile updates. This flaw allows authenticated attackers to arbitrarily change the email addresses of other user accounts, including administrative ones, by manipulating the membercookie parameter. With a CVSS score of 9.0, this vulnerability is highly severe, enabling complete compromise of confidentiality, integrity, and availability (AV:N/AC:L/Au:S/C:C/I:C/A:C). While not actively exploited in the wild according to KEV and Hot List data, a public exploit (EDB-4661) exists, demonstrating its exploitability, though it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.09CPE matchmatch criteria | cpe:2.3:a:deluxebb:deluxebb:1.09:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.