Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2006-0632

Опубликовано: 10 фев. 2006
Источник: ubuntu
Приоритет: medium
CVSS2: 6.4

Описание

The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establishing a password, which makes it easier for remote attackers to obtain the key and modify passwords for existing accounts or create new accounts.

РелизСтатусПримечание
dapper

ignored

end of life
devel

DNE

edgy

ignored

end of life, was needed
feisty

released

2.0.21-6
gutsy

released

2.0.21-6
hardy

released

2.0.21-6
intrepid

released

2.0.21-6
jaunty

DNE

karmic

DNE

upstream

needs-triage

Показывать по

Ссылки на источники

6.4 Medium

CVSS2

Связанные уязвимости

nvd
почти 20 лет назад

The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establishing a password, which makes it easier for remote attackers to obtain the key and modify passwords for existing accounts or create new accounts.

debian
почти 20 лет назад

The gen_rand_string function in phpBB 2.0.19 uses insufficiently rando ...

github
почти 4 года назад

The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establishing a password, which makes it easier for remote attackers to obtain the key and modify passwords for existing accounts or create new accounts.

6.4 Medium

CVSS2