CVE-2008-4102 (joomla) [Sitemap] - HeapOverflow Computer Security Community & Forums : Heap Overflow.com

PDA

View Full Version : CVE-2008-4102 (joomla)


Heap
20-09-08, 03:08
Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP's mt_rand function, as demonstrated by guessing password reset tokens, a different vulnerability than CVE-2008-3681.

More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4102)