PT-2008-1794 · Webportal · Webportal Cms

The:Paradox

·

Publicado

2008-01-08

·

Atualizado

2024-02-09

·

CVE-2008-0141

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WebPortal CMS version 0.6-beta
Description The issue allows remote attackers to obtain access to any account via a lostpass action because the actions.php file in WebPortal CMS generates predictable passwords containing only the time of day.
Recommendations For WebPortal CMS version 0.6-beta, consider modifying the password generation mechanism in the actions.php file to produce more secure and unpredictable passwords. As a temporary workaround, restrict access to the lostpass action to minimize the risk of exploitation.

Exploit

Correção

Use of Insufficiently Random Values

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-0141

Produtos afetados

Webportal Cms