Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The make_password function in ipsclass.php in Invision Power Board (IPB) 2.1.4 uses random data generated from partially predictable seeds to create the authentication code that is sent by e-mail to a user with a lost password, which might make it easier for remote attackers to guess the code and change the password for an IPB account, possibly involving millions of requests.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Invision Power Board 'ipsclass.php' make_password 功能认证代码创建漏洞
Vulnerability Description
Invision Power Board (IPB) 2.1.4的ipsclass.php中的make_password功能使用从可部分预知的启动源生成的随机数据来创建认证代码(通过电子邮件发送给遗失密码的用户),这可使远程攻击者更容易猜出代码并更改IPB帐号的密码(可能通过发起数百万次的请求)。
CVSS Information
N/A
Vulnerability Type
N/A