Vulnerabilities > CVE-2017-5214 - Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Codextrous B2J Contact 2.1.12
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows prediction of a uniqid value based on knowledge of a time value. This makes it easier to read arbitrary uploaded files.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
Packetstorm
data source | https://packetstormsecurity.com/files/download/151029/joomlacodextrous2117-shell.txt |
id | PACKETSTORM:151029 |
last seen | 2019-01-08 |
published | 2019-01-06 |
reporter | KingSkrupellos |
source | https://packetstormsecurity.com/files/151029/Joomla-Codextrous-B2jcontact-2.1.17-Shell-Upload.html |
title | Joomla Codextrous B2jcontact 2.1.17 Shell Upload |