CVE-2006-4078
pm.php (aka the PM system) in DeluxeBB 1.08, and possibly earlier, allows remote attackers to bypass authentication by providing an arbitrary username in the membercookie cookie parameter.
Date published : 2006-08-10
http://www.securityfocus.com/bid/19418
http://www.securityfocus.com/archive/1/442464/100/0/threaded
