Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wf9j-wrqc-3h9g

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote attackers to defeat protection mechanisms based on randomization by predicting a return value, as demonstrated by the authid protection mechanism.

Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote attackers to defeat protection mechanisms based on randomization by predicting a return value, as demonstrated by the authid protection mechanism.

EPSS

Процентиль: 57%
0.00345
Низкий

Связанные уязвимости

nvd
почти 15 лет назад

Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote attackers to defeat protection mechanisms based on randomization by predicting a return value, as demonstrated by the authid protection mechanism.

EPSS

Процентиль: 57%
0.00345
Низкий