VulnerabilityModified
CVE-2006-0866
PunBB 1.2.10 and earlier allows remote attackers to conduct brute force guessing attacks for an account's password, which may be as short as 4 characters.
MEDIUM 5.0EPSS 1.37%
Does this matter?
Lower severity and a low EPSS score (1.37%). Track it; it rarely justifies an emergency change on its own.
Description
PunBB 1.2.10 and earlier allows remote attackers to conduct brute force guessing attacks for an account's password, which may be as short as 4 characters.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.37% probability · 70th percentile
- CISA KEV
- Not listed
- Affected
- punbb/punbb
- Source
- cve@mitre.org
References
- http://www.neosecurityteam.net/advisories/Advisory-15.txt
- http://www.securityfocus.com/archive/1/425630/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24838
- http://www.neosecurityteam.net/advisories/Advisory-15.txt
- http://www.securityfocus.com/archive/1/425630/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24838
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.