actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it easier for remote attackers to obtain access to any account via a lostpass action.
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/27145 | vdb entry exploit broken link third party advisory |
https://www.exploit-db.com/exploits/4835 | third party advisory vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/39486 | vdb entry |