PT-2002-1297 · Dcforum · Dcforum

Published

2002-05-16

·

Updated

2016-10-18

·

CVE-2002-0226

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DCForum versions 6.x and 2000
Description The issue allows remote attackers to request a new password on behalf of another user and calculate the new password using the sessionID. This is due to the retrieve password.pl script generating predictable new passwords based on a sessionID.
Recommendations For DCForum versions 6.x and 2000, consider modifying the retrieve password.pl script to generate truly random and unique passwords, rather than basing them on the sessionID, to prevent attackers from calculating the new password. As a temporary workaround, restrict access to the retrieve password.pl script to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0226

Affected Products

Dcforum