CVE-2008-4102

Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP's mt_rand function, as demonstrated by guessing password reset tokens, a different vulnerability than CVE-2008-3681.


We have discovered 195,641 live websites that are affected by CVE-2008-4102.

Run a Free Instant Scan




Affected Software

Product  Joomla
Category Content Management System
Vulnerable Domains195,641 live websites (95% of Joomla install base)
Vulnerable Versions
  • from 0 through 1.5.7
Vulnerable Versions Count1 versions ( 0.97% of all versions)



Details

  • Published - Sep 19, 2008
  • Updated - Aug 7, 2024

Website Distribution by Country

Number of websites using CVE-2008-4102
United States14,486 websites



Italy51,181 websites
Russia13,611 websites
GB12,086 websites
Poland11,933 websites
Germany10,934 websites
Netherlands8,337 websites
Australia6,542 websites
South Africa6,336 websites
France4,738 websites

Website Distribution by TLD

Number of websites using CVE-2008-4102
.com48,426 websites
.it33,475 websites
.ru11,465 websites
.pl8,465 websites
.org6,193 websites
.co.uk5,791 websites
.nl5,728 websites
.de5,403 websites
.com.au4,672 websites
.net4,423 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2008-4102

Top websites that are affected by CVE-2008-4102. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.de Germany*,***
*******.**.ca Canada*,***
***********.**.za South Africa**,***
**************.se Sweden**,***
***************.com Italy**,***
*********.com GB**,***
*****.**.uk GB**,***
************.com Germany**,***
*********************.com United States**,***
****.pl Poland**,***
See full domain list

FAQ

A total of 195,641 websites have been identified as vulnerable to CVE-2008-4102, based on global website indexing conducted by WebTechSurvey.
The Joomla is affected by the CVE-2008-4102 vulnerability.
Joomla versions up to and including 1.5.7 are vulnerable to CVE-2008-4102.