PT-2006-1690 · Invision · Invision Power Board
Published
2006-02-10
·
Updated
2013-01-03
·
CVE-2006-0633
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Invision Power Board version 2.1.4
Description
The issue concerns the generation of authentication codes for lost passwords. Specifically, the
make password function in ipsclass.php uses random data generated from partially predictable seeds, which could make it easier for remote attackers to guess the code. This might allow attackers to change the password for an account, potentially involving a large number of requests.Recommendations
For Invision Power Board version 2.1.4, consider modifying the
make password function to use more unpredictable seeds for generating authentication codes, or implement additional security measures to prevent brute-force guessing of the authentication code. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Invision Power Board