retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to request a new password on behalf of another user and use the sessionID to calculate the new password for that user.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2002-05-16 04:00
Updated : 2025-04-03 01:03
NVD link : CVE-2002-0226
Mitre link : CVE-2002-0226
CVE.ORG link : CVE-2002-0226
JSON object : View
Products Affected
dcscripts
- dcforum
CWE