Record summary

CVE-2006-4068 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.

Description

The pswd.js script relies on the client to calculate whether a username and password match hard-coded hashed values for a server, and uses a hashing scheme that creates a large number of collisions, which makes it easier for remote attackers to conduct offline brute force attacks. NOTE: this script might also allow attackers to generate the server-side "secret" URL without determining the original password, but this possibility was not discussed by the original researcher.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBPSWD.JS - Insecure Password HashExploitDB exploitby Gianstefano MonniNot analyzed1 file
ExploitDB

PoC details

References

4