CVE
- Id
- 4618
- CVE No.
- CVE-2002-0226
- Status
- Entry
- Description
- retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to request a new password on behalf of another user and use the sessionID to calculate the new password for that user.
- Phase
- Votes
- Comments