6.4
CVSSv2

CVE-2006-0632

Published: 10/02/2006 Updated: 19/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establishing a password, which makes it easier for remote malicious users to obtain the key and modify passwords for existing accounts or create new accounts.

Vulnerable Product Search on Vulmon Subscribe to Product

phpbb group phpbb 2.0.5

phpbb group phpbb 2.0.7a

phpbb group phpbb 2.0.8

phpbb group phpbb 2.0.11

phpbb group phpbb 2.0.1

phpbb group phpbb 2.0.13

phpbb group phpbb 2.0.16

phpbb group phpbb 2.0.3

phpbb group phpbb 2.0 rc2

phpbb group phpbb 2.0 rc1

phpbb group phpbb 2.0.19

phpbb group phpbb 2.0.4

phpbb group phpbb 2.0.12

phpbb group phpbb 2.0.9

phpbb group phpbb 2.0.7

phpbb group phpbb 2.0.8a

phpbb group phpbb 2.0.6d

phpbb group phpbb 2.0.2

phpbb group phpbb 2.0.14

phpbb group phpbb 2.0.10

phpbb group phpbb 2.0.6c

phpbb group phpbb 2.0.15

phpbb group phpbb 2.0 rc4

phpbb group phpbb 2.0.6

phpbb group phpbb 2.0.0

phpbb group phpbb 2.0.17

phpbb group phpbb 2.0 rc3

phpbb group phpbb 2.0.18

phpbb group phpbb 2.0 beta1

Vendor Advisories

Debian Bug report logs - #500086 CVE-2008-4125: phpbb2 leaks state of php random number generator Package: phpbb2; Maintainer for phpbb2 is (unknown); Reported by: Stefan Fritsch <sf@sfritschde> Date: Wed, 24 Sep 2008 21:48:06 UTC Severity: grave Tags: security Found in version phpbb2/2021-7 Fixed in version phpbb2/20 ...