OSVDB ID: 2038

Title: DCForum retrieve_password.pl Predictable Password

Info

Disclosure

Jan 31, 2002

Discovery

Unknown

Dates

Exploit

Jan 31, 2002

Solution

Unknown

Description

DCForum contains a flaw that allows a remote attacker to predict newly created account passwords. The issue is due to a flaw in the method retrieve_password.pl uses when generating passwords. New passwords are created based on user information and session ID information, which is easily predictable.

Classification

Location: Remote/Network Access Required
Attack Type: Authentication Management
Impact: Loss of Integrity
Exploit: Exploit Available
Disclosure: OSVDB Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, the vendor has released a patch to address this vulnerability.

Products

DCScripts

DCForum

5.0
6.0
6.21

DCForum 2000

1.0

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/36218