6.4
CVSSv2

CVE-2006-0632

Published: 10/02/2006 Updated: 19/10/2018
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establishing a password, which makes it easier for remote malicious users to obtain the key and modify passwords for existing accounts or create new accounts.

Vulnerable Product Search on Vulmon Subscribe to Product

phpbb group phpbb 2.0.0

phpbb group phpbb 2.0.15

phpbb group phpbb 2.0.16

phpbb group phpbb 2.0.6

phpbb group phpbb 2.0.6c

phpbb group phpbb 2.0_beta1

phpbb group phpbb 2.0_rc1

phpbb group phpbb 2.0.13

phpbb group phpbb 2.0.14

phpbb group phpbb 2.0.4

phpbb group phpbb 2.0.5

phpbb group phpbb 2.0.8a

phpbb group phpbb 2.0.9

phpbb group phpbb 2.0.1

phpbb group phpbb 2.0.10

phpbb group phpbb 2.0.17

phpbb group phpbb 2.0.18

phpbb group phpbb 2.0.6d

phpbb group phpbb 2.0.7

phpbb group phpbb 2.0_rc2

phpbb group phpbb 2.0_rc3

phpbb group phpbb 2.0.11

phpbb group phpbb 2.0.12

phpbb group phpbb 2.0.19

phpbb group phpbb 2.0.2

phpbb group phpbb 2.0.3

phpbb group phpbb 2.0.7a

phpbb group phpbb 2.0.8

phpbb group phpbb 2.0_rc4

Vendor Advisories

Debian Bug report logs - #500086 CVE-2008-4125: phpbb2 leaks state of php random number generator Package: phpbb2; Maintainer for phpbb2 is (unknown); Reported by: Stefan Fritsch <sf@sfritschde> Date: Wed, 24 Sep 2008 21:48:06 UTC Severity: grave Tags: security Found in version phpbb2/2021-7 Fixed in version phpbb2/20 ...