cve/2013/CVE-2013-6386.md
2024-05-26 14:27:05 +02:00

703 B

CVE-2013-6386

Description

Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack.

POC

Reference

No PoCs from references.

Github