7.5

CVE-2008-0141

Exploit
actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it easier for remote attackers to obtain access to any account via a lostpass action.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Webportal Cms ProjectWebportal Cms Version0.6.0 Updatebeta
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.31% 0.899
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-330 Use of Insufficiently Random Values

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

http://www.securityfocus.com/bid/27145
Third Party Advisory
Exploit
Broken Link
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/39486
VDB Entry
https://www.exploit-db.com/exploits/4835
Third Party Advisory
Exploit
VDB Entry