Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The gen_rand_string function in phpBB 2.0.19 uses insufficiently random data (small value space) to create the activation key ("validation ID") that is sent by e-mail when establishing a password, which makes it easier for remote attackers to obtain the key and modify passwords for existing accounts or create new accounts.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
phpBB gen_rand_string功能电子邮件激活密钥安全信息泄露漏洞
Vulnerability Description
phpBB 2.0.19中的gen_rand_string功能使用随机数据(小值空间)创建将在建立密码时通过电子邮件发送的激活密钥("验证 ID"),这使得远程攻击者更容易获取密钥并修改现有帐户的密码或创建新帐户。
CVSS Information
N/A
Vulnerability Type
N/A