{ "id": "CVE-2008-4905", "sourceIdentifier": "cve@mitre.org", "published": "2008-11-04T00:58:40.227", "lastModified": "2009-01-29T06:57:42.530", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Typo 5.1.3 and earlier uses a hard-coded salt for calculating password hashes, which makes it easier for attackers to guess passwords via a brute force attack." }, { "lang": "es", "value": "Typo 5.1.3 y anteriores utiliza una semilla scrita en c\u00f3digo para el c\u00e1lculo de los hashes de contrase\u00f1as, lo cual facilita a los atacantes adivinar las contrase\u00f1as a trav\u00e9s de un ataque de fuerza bruta." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 5.0 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 10.0, "impactScore": 2.9, "acInsufInfo": true, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-310" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:*:*:*:*:*:*:*:*", "versionEndIncluding": "5.1.3", "matchCriteriaId": "1E3019EC-DA80-4761-B832-964F6EF93A65" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:1.6:*:*:*:*:*:*:*", "matchCriteriaId": "8AB16906-D886-490E-B677-96E498869033" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:1.6.8:*:*:*:*:*:*:*", "matchCriteriaId": "AA278206-6FE9-47B0-A2C5-29DB5FBA209D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:2.0.0:*:*:*:*:*:*:*", "matchCriteriaId": "B47D305A-E52B-487C-A224-A877B88153F7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:2.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "4CF012B6-1435-4030-AD9A-62DB01DE0662" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:2.0.5:*:*:*:*:*:*:*", "matchCriteriaId": "11CBA97F-C726-4C89-8669-3B54A20910B2" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:2.0.6:*:*:*:*:*:*:*", "matchCriteriaId": "CF0A64C3-BE11-4876-9080-9F48BE9FB1D6" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:2.5.0:*:*:*:*:*:*:*", "matchCriteriaId": "36A454B2-25F5-4D11-BB6F-8E3B59FFB0FF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:2.5.1:*:*:*:*:*:*:*", "matchCriteriaId": "DAD9ECE7-068C-45A7-9E84-5F39C16EC163" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:2.5.2:*:*:*:*:*:*:*", "matchCriteriaId": "FCF5981C-6983-46E3-92E5-8AD5732CAF5A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:2.5.3:*:*:*:*:*:*:*", "matchCriteriaId": "829B4A24-B296-4998-9660-DFCCC84B5737" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:2.5.4:*:*:*:*:*:*:*", "matchCriteriaId": "55B3F7BE-6A7F-4DF6-A8A5-255C80AC5394" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:2.5.5:*:*:*:*:*:*:*", "matchCriteriaId": "2CACF067-89CB-4E95-9765-F440065DDDE4" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:2.5.6:*:*:*:*:*:*:*", "matchCriteriaId": "57BB7A8C-1F33-488A-AF97-422105AB1CF7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:2.5.7:*:*:*:*:*:*:*", "matchCriteriaId": "C43C4381-76D1-4E4D-929D-57CF7985268E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:2.5.8:*:*:*:*:*:*:*", "matchCriteriaId": "B2169F77-8CDF-494F-8A5B-FBFA423F508A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:2.6.0:*:*:*:*:*:*:*", "matchCriteriaId": "F311CEC8-F619-4F79-A434-6BCB8505F1F3" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:3.99.0:*:*:*:*:*:*:*", "matchCriteriaId": "A9C58BA0-8E59-43BF-9558-E050C29AF181" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:3.99.1:*:*:*:*:*:*:*", "matchCriteriaId": "10174180-CBD7-4481-A067-EB3CEA93A362" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:3.99.2:*:*:*:*:*:*:*", "matchCriteriaId": "96B6FF23-B700-4B0D-8FA5-1CDED4E9A54F" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:3.99.3:*:*:*:*:*:*:*", "matchCriteriaId": "E2A09B06-DF95-4112-9FC8-847BDBCAEBFD" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:3.99.4:*:*:*:*:*:*:*", "matchCriteriaId": "DF324FFC-353B-47C2-809E-1AF1003DBD6B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:4.0.0:*:*:*:*:*:*:*", "matchCriteriaId": "634E850B-5C36-497C-9175-FBA1F5FF4C1A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:4.1.1:*:*:*:*:*:*:*", "matchCriteriaId": "7A845374-834E-4696-A9C2-A32C83044CBF" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:5.0.2:*:*:*:*:*:*:*", "matchCriteriaId": "37FBAA0E-8E1D-4E8B-A08D-AA477FEDA85D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:5.0.3:*:*:*:*:*:*:*", "matchCriteriaId": "9D419017-2B6C-4DF9-8B98-F74840721BED" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:5.0.3.98:*:*:*:*:*:*:*", "matchCriteriaId": "028B2D4F-8BB6-4DB9-A1A3-3BB88407639E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:5.0.3.98.1:*:*:*:*:*:*:*", "matchCriteriaId": "7FD1F53D-1911-445A-8230-748F2DD20621" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:5.1:*:*:*:*:*:*:*", "matchCriteriaId": "CF128B29-BFF1-4E99-A1B4-999C14FDB3AE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:5.1.1:*:*:*:*:*:*:*", "matchCriteriaId": "4225B42A-48BF-4AD3-ACB7-4806EA785B1E" }, { "vulnerable": true, "criteria": "cpe:2.3:a:typosphere:typo:5.1.2:*:*:*:*:*:*:*", "matchCriteriaId": "447033D5-7C0E-4184-AF79-E1CB31BD6AE2" } ] } ] } ], "references": [ { "url": "http://securityreason.com/securityalert/4550", "source": "cve@mitre.org" }, { "url": "http://www.securityfocus.com/archive/1/497970", "source": "cve@mitre.org" } ] }