info
discussion
exploit
solution
references
WordPress Random Password Generation Insufficient Entropy Weakness
References:
WordPress 2.6.2
(Wordpress)
WordPress Homepage
(WordPress)
Wordpress user_login Column SQL Truncation Vulnerability
(Stefan Esser)
mt_srand and not so random numbers
(Stefan Esser)
Privacy Statement
Copyright 2010, SecurityFocus