PT-2002-1297 · Dcforum · Dcforum

Publicado

2002-05-16

·

Atualizado

2016-10-18

·

CVE-2002-0226

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DCForum versions 6.x and 2000
Description The issue allows remote attackers to request a new password on behalf of another user and calculate the new password using the sessionID. This is due to the retrieve password.pl script generating predictable new passwords based on a sessionID.
Recommendations For DCForum versions 6.x and 2000, consider modifying the retrieve password.pl script to generate truly random and unique passwords, rather than basing them on the sessionID, to prevent attackers from calculating the new password. As a temporary workaround, restrict access to the retrieve password.pl script to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0226

Produtos afetados

Dcforum