Joomla! Predictable Password Generation Vulnerability
BID:52535
Info
Joomla! Predictable Password Generation Vulnerability
| Bugtraq ID: | 52535 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 16 2012 12:00AM |
| Updated: | Mar 16 2012 12:00AM |
| Credit: | George Argyros and Aggelos Kiayias |
| Vulnerable: |
Joomla Joomla! 2.5.2 Joomla Joomla! 2.5.1 Joomla Joomla! 2.5 |
| Not Vulnerable: |
Joomla Joomla! 2.5.3 |
Discussion
Joomla! Predictable Password Generation Vulnerability
Joomla! is prone to an insecure password generation vulnerability.
Successfully exploiting this issue may allow an attacker to guess generated passwords.
Joomla! versions 2.5.0 through 2.5.2. are vulnerable.
Joomla! is prone to an insecure password generation vulnerability.
Successfully exploiting this issue may allow an attacker to guess generated passwords.
Joomla! versions 2.5.0 through 2.5.2. are vulnerable.
Exploit / POC
Joomla! Predictable Password Generation Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
Joomla! Predictable Password Generation Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
Joomla! Predictable Password Generation Vulnerability
References:
References: