3.5

CVE-2008-1484

The password reset feature in PunBB 1.2.16 and earlier uses predictable random numbers based on the system time, which allows remote authenticated users to determine the new password via a brute force attack on a seed that is based on the approximate creation time of the targeted account.  NOTE: this issue might be related to CVE-2006-5737.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PunbbPunbb Version1.0
PunbbPunbb Version1.0.1
PunbbPunbb Version1.0_alpha
PunbbPunbb Version1.0_beta1
PunbbPunbb Version1.0_beta2
PunbbPunbb Version1.0_beta3
PunbbPunbb Version1.0_rc1
PunbbPunbb Version1.0_rc2
PunbbPunbb Version1.1
PunbbPunbb Version1.1.1
PunbbPunbb Version1.1.2
PunbbPunbb Version1.1.3
PunbbPunbb Version1.1.4
PunbbPunbb Version1.1.5
PunbbPunbb Version1.2
PunbbPunbb Version1.2.1
PunbbPunbb Version1.2.2
PunbbPunbb Version1.2.3
PunbbPunbb Version1.2.4
PunbbPunbb Version1.2.5
PunbbPunbb Version1.2.6
PunbbPunbb Version1.2.7
PunbbPunbb Version1.2.8
PunbbPunbb Version1.2.9
PunbbPunbb Version1.2.10
PunbbPunbb Version1.2.11
PunbbPunbb Version1.2.12
PunbbPunbb Version1.2.13
PunbbPunbb Version1.2.14
PunbbPunbb Version1.2.15
PunbbPunbb Version1.2.16
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.52% 0.903
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://osvdb.org/45561
http://punbb.org/download/changelogs/1.2.16_to_1.2.17.txt
http://punbb.org/forums/viewtopic.php?id=18460
http://secunia.com/advisories/29043
Vendor Advisory
http://sektioneins.de/advisories/SE-2008-01.txt
http://www.securityfocus.com/archive/1/488408/100/200/threaded
http://www.securityfocus.com/bid/27908
Patch
https://www.exploit-db.com/exploits/5165