« Volver al listado

CVE-2002-0226

Estado: ModificadaAlta (7.5)—

retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to request a new password on behalf of another user and use the sessionID to calculate the new password for that user.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2002-0226",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": true,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2002-05-16T04:00:00.000",
  "references": [
    {
      "url": "http://marc.info/?l=bugtraq&m=101258311519504&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.dcscripts.com/bugtrac/DCForumID7/3.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.iss.net/security_center/static/8044.php",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/2038",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/3866",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/4014",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=101258311519504&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.dcscripts.com/bugtrac/DCForumID7/3.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.iss.net/security_center/static/8044.php",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/2038",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/3866",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/4014",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to request a new password on behalf of another user and use the sessionID to calculate the new password for that user."
    },
    {
      "lang": "es",
      "value": "retrieve_password.pl en DCForum 6.x y 2000 genera nuevas contraseñas basadas en un identificador de sesión, lo que permite a atacantes remotos pedir una nueva contraseña aprovechándose de otro usuarios y usar el identificador de sesión para calcular la nueva contraseña de ese usuario."
    }
  ],
  "lastModified": "2026-06-16T21:57:01.933",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dcscripts:dcforum:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "391D155A-F680-4D9E-AD43-7D6A26EF5557"
            },
            {
              "criteria": "cpe:2.3:a:dcscripts:dcforum:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5FF2D08-2062-41E8-988F-40A2B6F95ED5"
            },
            {
              "criteria": "cpe:2.3:a:dcscripts:dcforum:6.21:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD46CB65-8F52-400A-A505-6C26426C0222"
            },
            {
              "criteria": "cpe:2.3:a:dcscripts:dcforum:2000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ABABA965-16FF-44F4-8C4C-F80F081672ED"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}