WordPress Random Password Generation Insufficient Entropy Weakness
BID:31115
Info
WordPress Random Password Generation Insufficient Entropy Weakness
| Bugtraq ID: | 31115 |
| Class: | Design Error |
| CVE: |
CVE-2008-4107 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2008 12:00AM |
| Updated: | May 07 2015 05:24PM |
| Credit: | Stefan Esser, iso^kpsbr |
| Vulnerable: |
WordPress WordPress 2.6.1 |
| Not Vulnerable: |
WordPress WordPress 2.6.2 |
Discussion
WordPress Random Password Generation Insufficient Entropy Weakness
WordPress is prone to a weakness in the entropy of generated passwords.
Successfully exploiting this issue may allow an attacker to guess randomly generated passwords.
WordPress 2.6.1 is vulnerable; other versions may also be affected.
WordPress is prone to a weakness in the entropy of generated passwords.
Successfully exploiting this issue may allow an attacker to guess randomly generated passwords.
WordPress 2.6.1 is vulnerable; other versions may also be affected.
Exploit / POC
WordPress Random Password Generation Insufficient Entropy Weakness
The following exploit is available:
The following exploit is available:
Solution / Fix
WordPress Random Password Generation Insufficient Entropy Weakness
Solution:
The vendor has addressed this issue in WordPress 2.6.2. Contact the vendor for more information.
Solution:
The vendor has addressed this issue in WordPress 2.6.2. Contact the vendor for more information.
References
WordPress Random Password Generation Insufficient Entropy Weakness
References:
References:
- WordPress 2.6.2 (Wordpress)
- Wordpress church_admin Plugin "id" Cross-Site Scripting Vulnerability (Sammy Forgit)
- Wordpress user_login Column SQL Truncation Vulnerability (Stefan Esser)
- mt_srand and not so random numbers (Stefan Esser)