First published: Mon Nov 06 2006(Updated: )
PunBB uses a predictable cookie_seed value that can be derived from the time of registration of the superadmin account (installation time), which might allow local users to perform unauthorized actions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PunBB | =1.2.14 | |
=1.2.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5737 is considered a medium severity vulnerability due to its potential to allow unauthorized actions by local users.
To fix CVE-2006-5737, update to a newer version of PunBB that addresses this vulnerability, or change the cookie_seed value to be less predictable.
CVE-2006-5737 affects users of PunBB version 1.2.14 where the predictable cookie_seed can be exploited.
Due to CVE-2006-5737, local users could potentially perform actions reserved for the superadmin account.
A temporary workaround for CVE-2006-5737 is to limit access to the affected system to trusted users until the software is updated.