Vulnerabilities > CVE-2017-5214 - Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Codextrous B2J Contact

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
codextrous
CWE-335

Summary

The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows prediction of a uniqid value based on knowledge of a time value. This makes it easier to read arbitrary uploaded files.

Vulnerable Configurations

Part Description Count
Application
Codextrous
1

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/151029/joomlacodextrous2117-shell.txt
idPACKETSTORM:151029
last seen2019-01-08
published2019-01-06
reporterKingSkrupellos
sourcehttps://packetstormsecurity.com/files/151029/Joomla-Codextrous-B2jcontact-2.1.17-Shell-Upload.html
titleJoomla Codextrous B2jcontact 2.1.17 Shell Upload