CVE Database
/

CVE-2013-6386

Back to search

CVE-2013-6386

Published: Dec 7, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack.

VendorProductVersions

n/a

n/a

affected
n/a

References

56148
third-party-advisory
x_refsource_SECUNIA
DSA-2828
vendor-advisory
x_refsource_DEBIAN
DSA-2804
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now