The make_password function in ipsclass.php in Invision Power Board (IPB) 2.1.4 uses random data generated from partially predictable seeds to create the authentication code that is sent by e-mail to a user with a lost password, which might make it easier for remote attackers to guess the code and change the password for an IPB account, possibly involving millions of requests.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2006-02-10T11:00:00Z

Updated: 2024-09-16T19:39:59.705Z

Reserved: 2006-02-10T00:00:00Z

Link: CVE-2006-0633

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2006-02-10T11:02:00.000

Modified: 2024-11-21T00:06:57.970

Link: CVE-2006-0633

cve-icon Redhat

No data.