PseudoRandom-php.txt...

- AV AC AU C I A
发布: 2006-02-07
修订: 2025-04-13

Due to poor design the gen_rand_string() can only generate up to 1 million hashes or random strings. This allow an attacker to reset any account through the lost password request form by "predicting" the validation id and the new password for the account. Vulnerabilities verified on phpBB 2.0.19 and IPB 2.1.4.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息