Joomla! 1.5 before 1.5.7 initializes PHPs PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHPs mt_rand function, as demonstrated by guessing password reset tokens, a different vulnerability than CVE-2008-3681.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Joomla | Joomla | 1.5 (including) | 1.5 (including) |
Joomla | Joomla | 1.5.1 (including) | 1.5.1 (including) |
Joomla | Joomla | 1.5.2 (including) | 1.5.2 (including) |
Joomla | Joomla | 1.5.3 (including) | 1.5.3 (including) |
Joomla | Joomla | 1.5.4 (including) | 1.5.4 (including) |
Joomla | Joomla | 1.5.5 (including) | 1.5.5 (including) |
Joomla | Joomla | 1.5.6 (including) | 1.5.6 (including) |