45561vdb entry
http://osvdb.org/45561 CVE-2008-1484
PunBB 1.2.16 - Blind Password Recovery
Record summary
CVE-2008-1484 has a selected CVSS score of 3.5; EIP currently links 1 catalogued exploit.
Description
The password reset feature in PunBB 1.2.16 and earlier uses predictable random numbers based on the system time, which allows remote authenticated users to determine the new password via a brute force attack on a seed that is based on the approximate creation time of the targeted account. NOTE: this issue might be related to CVE-2006-5737.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPunBB 1.2.16 - Blind Password RecoveryExploitDB exploitby EpiBiteNot analyzed1 file
References
9punbb.orgConfirmation
http://punbb.org/download/changelogs/1.2.16_to_1.2.17.txt punbb.orgConfirmation
http://punbb.org/forums/viewtopic.php?id=18460 29043Third-party advisory
http://secunia.com/advisories/29043 sektioneins.de
http://sektioneins.de/advisories/SE-2008-01.txt 20080220 Advisory SE-2008-01: PunBB Blind Password Recovery Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/488408/100/200/threaded 27908vdb entry
http://www.securityfocus.com/bid/27908 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-1484 5165exploit
https://www.exploit-db.com/exploits/5165