Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote attackers to defeat protection mechanisms based on randomization by predicting a return value, as demonstrated by the authid protection mechanism.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Zikula rand和srand PHP函数加密问题漏洞
Vulnerability Description
Zikula 是一个用于构建和维护Web站点的php应用程序框架。 Zikula 1.3.1之前版本使用了rand和srand PHP函数进行随机数产生。远程攻击者更容易通过预测返回值,攻破基于随机化的保护机制。
CVSS Information
N/A
Vulnerability Type
N/A