PT-2008-1794 · Webportal · Webportal Cms
The:Paradox
·
Publicado
2008-01-08
·
Atualizado
2024-02-09
·
CVE-2008-0141
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
WebPortal CMS version 0.6-beta
Description
The issue allows remote attackers to obtain access to any account via a lostpass action because the
actions.php file in WebPortal CMS generates predictable passwords containing only the time of day.Recommendations
For WebPortal CMS version 0.6-beta, consider modifying the password generation mechanism in the
actions.php file to produce more secure and unpredictable passwords. As a temporary workaround, restrict access to the lostpass action to minimize the risk of exploitation.Exploit
Correção
Use of Insufficiently Random Values
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Webportal Cms