CVE-2016-2564

Severity CVSS v4.0:
Pending analysis
Type:
CWE-331 Insufficient Entropy
Publication date:
23/04/2017
Last modified:
20/04/2025

Description

Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the more_entropy flag. Attackers can guess an Invision Power Board session cookie if they can predict the exact time of cookie generation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:invisioncommunity:invision_power_board:*:*:*:*:*:*:*:* 4.1.8.1 (including)