Check out /libs/html.inc.php for the password authentication.

Basicly either the MD5 has to match, or the temporary password must match, and if so, it's converted to an MD5 password.

Look around this line on how ubb checks things:

Code
		if ((crypt($Password,$user['USER_PASSWORD']) != $user['USER_PASSWORD']) && (md5($Password) != $user['USER_PASSWORD'])) {


[Linked Image from siemons.org]