Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The my_rand function in functions.php in MyBB (aka MyBulletinBoard) before 1.4.12 does not properly use the PHP mt_rand function, which makes it easier for remote attackers to obtain access to an arbitrary account by requesting a reset of the account's password, and then conducting a brute-force attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
MyBB functions.php文件任意帐号访问漏洞
Vulnerability Description
MyBB(又名MyBulletinBoard)是MyBB团队开发的一套用PHP和MySQL开发的免费且基于Web的论坛软件。该软件具有简单易用、支持多国语言、可扩展等特点。 MyBB(又名MyBulletinBoard)1.4.12之前版本中的functions.php文件中的my_rand函数没有正确使用PHP mt_rand函数。远程攻击者更容易通过请求账户密码的重置并随即进行暴力攻击,获得对任意账户的访问。
CVSS Information
N/A
Vulnerability Type
N/A