Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-0633

Опубликовано: 10 фев. 2006
Источник: nvd
CVSS2: 6.4
EPSS Низкий

Описание

The make_password function in ipsclass.php in Invision Power Board (IPB) 2.1.4 uses random data generated from partially predictable seeds to create the authentication code that is sent by e-mail to a user with a lost password, which might make it easier for remote attackers to guess the code and change the password for an IPB account, possibly involving millions of requests.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:invisionpower:invision_power_board:2.1.4:*:*:*:*:*:*:*

EPSS

Процентиль: 66%
0.00504
Низкий

6.4 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

github
почти 4 года назад

The make_password function in ipsclass.php in Invision Power Board (IPB) 2.1.4 uses random data generated from partially predictable seeds to create the authentication code that is sent by e-mail to a user with a lost password, which might make it easier for remote attackers to guess the code and change the password for an IPB account, possibly involving millions of requests.

EPSS

Процентиль: 66%
0.00504
Низкий

6.4 Medium

CVSS2

Дефекты

CWE-287