CVE-2010-4728
08.02.2011, 22:00
Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote attackers to defeat protection mechanisms based on randomization by predicting a return value, as demonstrated by the authid protection mechanism.Enginsight
Vendor | Product | Version |
---|---|---|
zikula | zikula_application_framework | 𝑥 ≤ 1.2.5 |
zikula | zikula_application_framework | 1.1.2 |
zikula | zikula_application_framework | 1.2.1 |
zikula | zikula_application_framework | 1.2.2 |
zikula | zikula_application_framework | 1.2.3 |
zikula | zikula_application_framework | 1.2.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration