7.5
CVSSv3

CVE-2009-2158

Published: 22/06/2009 Updated: 15/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

account-recover.php in TorrentTrader Classic 1.09 chooses random passwords from an insufficiently large set, which makes it easier for remote malicious users to obtain a password via a brute-force attack.

Vulnerable Product Search on Vulmon Subscribe to Product

torrenttrader project torrenttrader 1.09

Exploits

[waraxe-2009-SA#074] - Multiple Vulnerabilities in TorrentTrader Classic 109 =============================================================================== Author: Janek Vind "waraxe" Date: 15 June 2009 Location: Estonia, Tartu Web: wwwwaraxeus/advisory-74html Description of vulnerable software: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ...