pm.php (aka the PM system) in DeluxeBB 1.08, and possibly earlier, allows remote attackers to bypass authentication by providing an arbitrary username in the membercookie cookie parameter.
- http://securityreason.com/securityalert/1381
No PoCs found on GitHub currently.