retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to request a new password on behalf of another user and use the sessionID to calculate the new password for that user.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2002-06-25T04:00:00
Updated: 2024-08-08T02:42:28.582Z
Reserved: 2002-05-01T00:00:00
Link: CVE-2002-0226
Vulnrichment
No data.
NVD
Status : Modified
Published: 2002-05-16T04:00:00.000
Modified: 2024-11-20T23:38:35.897
Link: CVE-2002-0226
Redhat
No data.