Record summary

CVE-2008-1484 has a selected CVSS score of 3.5; EIP currently links 1 catalogued exploit.

Description

The password reset feature in PunBB 1.2.16 and earlier uses predictable random numbers based on the system time, which allows remote authenticated users to determine the new password via a brute force attack on a seed that is based on the approximate creation time of the targeted account. NOTE: this issue might be related to CVE-2006-5737.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBPunBB 1.2.16 - Blind Password RecoveryExploitDB exploitby EpiBiteNot analyzed1 file
ExploitDB

PoC details

References

9