Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3265-vrfj-hjqg

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establishing a password, which makes it easier for remote attackers to obtain the key and modify passwords for existing accounts or create new accounts.

The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establishing a password, which makes it easier for remote attackers to obtain the key and modify passwords for existing accounts or create new accounts.

EPSS

Процентиль: 76%
0.0098
Низкий

Связанные уязвимости

ubuntu
почти 20 лет назад

The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establishing a password, which makes it easier for remote attackers to obtain the key and modify passwords for existing accounts or create new accounts.

nvd
почти 20 лет назад

The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establishing a password, which makes it easier for remote attackers to obtain the key and modify passwords for existing accounts or create new accounts.

debian
почти 20 лет назад

The gen_rand_string function in phpBB 2.0.19 uses insufficiently rando ...

EPSS

Процентиль: 76%
0.0098
Низкий