Ultimate PHP Board Weak Password Encryption Vulnerability
BID:13975
Info
Ultimate PHP Board Weak Password Encryption Vulnerability
| Bugtraq ID: | 13975 |
| Class: | Design Error |
| CVE: |
CVE-2005-2030 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2005 12:00AM |
| Updated: | Jun 16 2005 12:00AM |
| Credit: | "Alberto Trivero" <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
Ultimate PHP Board Ultimate PHP Board 1.9.6 Ultimate PHP Board Ultimate PHP Board 1.9 Ultimate PHP Board Ultimate PHP Board 1.8.2 Ultimate PHP Board Ultimate PHP Board 1.8 |
| Not Vulnerable: | |
Discussion
Ultimate PHP Board Weak Password Encryption Vulnerability
Ultimate PHP Board is prone to a weak password encryption vulnerability. This issue is due to a failure of the application to protect passwords with a sufficiently effective encryption scheme.
This issue may allow a malicious user to gain access to user and administrator passwords for the affected application.
Ultimate PHP Board is prone to a weak password encryption vulnerability. This issue is due to a failure of the application to protect passwords with a sufficiently effective encryption scheme.
This issue may allow a malicious user to gain access to user and administrator passwords for the affected application.
Exploit / POC
Ultimate PHP Board Weak Password Encryption Vulnerability
The following exploit has been provided:
The following exploit has been provided:
Solution / Fix
Ultimate PHP Board Weak Password Encryption Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Ultimate PHP Board Weak Password Encryption Vulnerability
References:
References:
- Ultimate PHP Board Homepage (Ultimate PHP Board)
- M4DR007-06SA (security advisory): Multiple vulnerabilities in UPB 1.9.6 GOLD ("Alberto Trivero"
) - Passwords Decrypter for UPB <= 1.9.6 ("Alberto Trivero"
)