Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Easily exploitable Pseudo Random Number generator in phpbb version 2.0.19 and under. Feb 05 2006 08:49AM
chinchilla gmail com
I. DESCRIPTION

Easily exploitable Pseudo Random Number generator in phpbb version 2.0.19 and under.

II. DETAILS

Due to poor design the gen_rand_string() can only generate upto 1 million hashes or random strings. This allow an attacker to reset any account through the lost password request form b...

[ more ]  





 

Privacy Statement
Copyright 2008, SecurityFocus