CVE-2006-0633
N/A
N/A
Summary
The make_password function in ipsclass.php in Invision Power Board (IPB) 2.1.4 uses random data generated from partially predictable seeds to create the authentication code that is sent by e-mail to a user with a lost password, which might make it easier for remote attackers to guess the code and change the password for an IPB account, possibly involving millions of requests.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://forums.invisionpower.com/lofiversion/index.php/t200085.html
- http://www.r-security.net/tutorials/view/readtutorial.php?id=4
References
- http://forums.invisionpower.com/lofiversion/index.php/t200085.html
- http://www.r-security.net/tutorials/view/readtutorial.php?id=4
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.