account-recover.php in TorrentTrader Classic 1.09 chooses random passwords from an insufficiently large set, which makes it easier for remote attackers to obtain a password via a brute-force attack.
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/51150 | vdb entry third party advisory |
http://www.securityfocus.com/bid/35369 | exploit vdb entry third party advisory broken link |
https://www.exploit-db.com/exploits/8958 | exploit vdb entry third party advisory |
http://www.securityfocus.com/archive/1/504294/100/0/threaded | mailing list vdb entry third party advisory broken link |
http://www.waraxe.us/advisory-74.html | exploit |