7.5
CVSSv2

CVE-2008-4102

Published: 18/09/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Joomla! 1.5 prior to 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for malicious users to guess the pseudo-random values produced by PHP's mt_rand function, as demonstrated by guessing password reset tokens, a different vulnerability than CVE-2008-3681.

Vulnerable Product Search on Vulmon Subscribe to Product

joomla joomla 1.5

joomla joomla 1.5.1

joomla joomla 1.5.2

joomla joomla 1.5.3

joomla joomla 1.5.4

joomla joomla 1.5.5

joomla joomla 1.5.6

Vendor Advisories

Debian Bug report logs - #500087 CVE-2008-4107: The rand and mt_rand functions in PHP produce weak random numbers Package: php5; Maintainer for php5 is Debian PHP Maintainers <pkg-php-maint@listsaliothdebianorg>; Source for php5 is src:php5 (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: W ...