class.userpeer.php in MFScripts YetiShare 3.5.2 up to and including 4.5.3 uses an insecure method of creating password reset hashes (based only on microtime), which allows an malicious user to guess the hash and set the password within a few hours by bruteforcing.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
mfscripts yetishare |