retrieve_password.pl in DCForum 6.x and 2000 generates predictable new passwords based on a sessionID, which allows remote attackers to request a new password on behalf of another user and use the sessionID to calculate the new password for that user.
| Software | From | Fixed in |
|---|---|---|
| dcscripts / dcforum | 6.21 | 6.21.x |
| dcscripts / dcforum | 2000 | 2000.x |
| dcscripts / dcforum | 5.0 | 5.0.x |
| dcscripts / dcforum | 6.0 | 6.0.x |