Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7g29-9v7v-cq9g

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The createRandomPassword function in includes/functions_common.php in Virtual War (aka VWar) 1.6.1 R2 uses a small range of values to select the seed argument for the PHP mt_srand function, which makes it easier for remote attackers to determine randomly generated passwords via a brute-force attack.

The createRandomPassword function in includes/functions_common.php in Virtual War (aka VWar) 1.6.1 R2 uses a small range of values to select the seed argument for the PHP mt_srand function, which makes it easier for remote attackers to determine randomly generated passwords via a brute-force attack.

EPSS

Процентиль: 48%
0.0025
Низкий

Связанные уязвимости

nvd
больше 13 лет назад

The createRandomPassword function in includes/functions_common.php in Virtual War (aka VWar) 1.6.1 R2 uses a small range of values to select the seed argument for the PHP mt_srand function, which makes it easier for remote attackers to determine randomly generated passwords via a brute-force attack.

EPSS

Процентиль: 48%
0.0025
Низкий