Description
retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to request a new password on behalf of another user and use the sessionID to calculate the new password for that user.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2002-0223 | retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to request a new password on behalf of another user and use the sessionID to calculate the new password for that user. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T02:42:28.582Z
Reserved: 2002-05-01T00:00:00.000Z
Link: CVE-2002-0226
No data.
Status : Deferred
Published: 2002-05-16T04:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2002-0226
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD