CVE-2008-4125: Infoleak
Published Sep 18, 2008
·Updated
The search function in phpBB 2.x provides a searchid value that leaks the state of PHP's PRNG, which allows remote attackers to obtain potentially sensitive information, as demonstrated by a cross-application attack against WordPress, a different vulnerability than CVE-2006-0632.
Affected Software
1 affected component
phpBB phpbb=2
Event History
Sep 18, 2008
CVE Published
via MITRE·05:47 PM
Data Sourced
via MITRE·05:47 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4125?
CVE-2008-4125 is classified as a medium severity vulnerability.
2
How do I fix CVE-2008-4125?
To fix CVE-2008-4125, upgrade to a more recent version of phpBB that addresses this security issue.
3
What type of vulnerability is CVE-2008-4125?
CVE-2008-4125 is an information disclosure vulnerability related to PHP's pseudo-random number generator.
4
What software is affected by CVE-2008-4125?
CVE-2008-4125 affects phpBB version 2.x.
5
Can CVE-2008-4125 lead to further attacks?
Yes, CVE-2008-4125 can potentially enable cross-application attacks, such as those against WordPress.