Vulnerability Description
The createRandomPassword function in includes/functions_common.php in Virtual War (aka VWar) 1.6.1 R2 uses a small range of values to select the seed argument for the PHP mt_srand function, which makes it easier for remote attackers to determine randomly generated passwords via a brute-force attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vwar | Virtual War | 1.6.1 |
Related Weaknesses (CWE)
References
- http://dmcdonald.net/vwar.txtExploit
- http://seclists.org/fulldisclosure/2010/Aug/235Exploit
- http://dmcdonald.net/vwar.txtExploit
- http://seclists.org/fulldisclosure/2010/Aug/235Exploit
FAQ
What is CVE-2010-5066?
CVE-2010-5066 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The createRandomPassword function in includes/functions_common.php in Virtual War (aka VWar) 1.6.1 R2 uses a small range of values to select the seed argument for the PHP mt_srand function, which make...
How severe is CVE-2010-5066?
CVE-2010-5066 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-5066?
Check the references section above for vendor advisories and patch information. Affected products include: Vwar Virtual War.