CVE-2009-2158: High severity torrenttrader vulnerability
account-recover.php in TorrentTrader Classic 1.09 chooses random passwords from an insufficiently large set, which makes it easier for remote attackers to obtain a password via a brute-force attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2158?
CVE-2009-2158 is considered a medium severity vulnerability due to its potential for exploitation through brute-force attacks.
How do I fix CVE-2009-2158?
To fix CVE-2009-2158, update your TorrentTrader Classic to a version that addresses the password generation issue.
What can attackers gain from exploiting CVE-2009-2158?
Attackers exploiting CVE-2009-2158 can gain unauthorized access to user accounts by successfully guessing weak passwords.
Is CVE-2009-2158 present in other versions of TorrentTrader?
CVE-2009-2158 is specifically associated with TorrentTrader Classic version 1.09, and other versions may not be affected.
How does CVE-2009-2158 facilitate brute-force attacks?
CVE-2009-2158 facilitates brute-force attacks by using a small subset of random passwords, making it easier for attackers to guess user passwords.