The password reset functionality in Joomla! 1.5.x through 1.5.24 uses weak random numbers, which makes it easier for remote attackers to change the passwords of arbitrary users via unspecified vectors.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Joomla! | Joomla | 1.5.0 (including) | 1.5.0 (including) |
| Joomla! | Joomla | 1.5.1 (including) | 1.5.1 (including) |
| Joomla! | Joomla | 1.5.2 (including) | 1.5.2 (including) |
| Joomla! | Joomla | 1.5.3 (including) | 1.5.3 (including) |
| Joomla! | Joomla | 1.5.4 (including) | 1.5.4 (including) |
| Joomla! | Joomla | 1.5.5 (including) | 1.5.5 (including) |
| Joomla! | Joomla | 1.5.6 (including) | 1.5.6 (including) |
| Joomla! | Joomla | 1.5.7 (including) | 1.5.7 (including) |
| Joomla! | Joomla | 1.5.8 (including) | 1.5.8 (including) |
| Joomla! | Joomla | 1.5.9 (including) | 1.5.9 (including) |
| Joomla! | Joomla | 1.5.10 (including) | 1.5.10 (including) |
| Joomla! | Joomla | 1.5.11 (including) | 1.5.11 (including) |
| Joomla! | Joomla | 1.5.12 (including) | 1.5.12 (including) |
| Joomla! | Joomla | 1.5.13 (including) | 1.5.13 (including) |
| Joomla! | Joomla | 1.5.14 (including) | 1.5.14 (including) |
| Joomla! | Joomla | 1.5.15 (including) | 1.5.15 (including) |
| Joomla! | Joomla | 1.5.15-rc (including) | 1.5.15-rc (including) |
| Joomla! | Joomla | 1.5.16 (including) | 1.5.16 (including) |
| Joomla! | Joomla | 1.5.17 (including) | 1.5.17 (including) |
| Joomla! | Joomla | 1.5.18 (including) | 1.5.18 (including) |
| Joomla! | Joomla | 1.5.19 (including) | 1.5.19 (including) |
| Joomla! | Joomla | 1.5.20 (including) | 1.5.20 (including) |
| Joomla! | Joomla | 1.5.21 (including) | 1.5.21 (including) |
| Joomla! | Joomla | 1.5.22 (including) | 1.5.22 (including) |
| Joomla! | Joomla | 1.5.23 (including) | 1.5.23 (including) |
| Joomla! | Joomla | 1.5.24 (including) | 1.5.24 (including) |