Vulnerability Details CVE-2016-2564
Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the more_entropy flag. Attackers can guess an Invision Power Board session cookie if they can predict the exact time of cookie generation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.8%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 4.3
Products affected by CVE-2016-2564
-
cpe:2.3:a:invisioncommunity:invision_power_board:2.0
-
cpe:2.3:a:invisioncommunity:invision_power_board:3.0.0
-
cpe:2.3:a:invisioncommunity:invision_power_board:3.0.1
-
cpe:2.3:a:invisioncommunity:invision_power_board:3.0.2
-
cpe:2.3:a:invisioncommunity:invision_power_board:3.0.4
-
cpe:2.3:a:invisioncommunity:invision_power_board:3.1.2
-
cpe:2.3:a:invisioncommunity:invision_power_board:3.3.0
-
cpe:2.3:a:invisioncommunity:invision_power_board:3.3.1
-
cpe:2.3:a:invisioncommunity:invision_power_board:3.3.2
-
cpe:2.3:a:invisioncommunity:invision_power_board:3.3.3
-
cpe:2.3:a:invisioncommunity:invision_power_board:3.3.4
-
cpe:2.3:a:invisioncommunity:invision_power_board:3.4.0
-
cpe:2.3:a:invisioncommunity:invision_power_board:3.4.1
-
cpe:2.3:a:invisioncommunity:invision_power_board:3.4.2
-
cpe:2.3:a:invisioncommunity:invision_power_board:3.4.3
-
cpe:2.3:a:invisioncommunity:invision_power_board:3.4.4
-
cpe:2.3:a:invisioncommunity:invision_power_board:3.4.5
-
cpe:2.3:a:invisioncommunity:invision_power_board:3.4.6
-
cpe:2.3:a:invisioncommunity:invision_power_board:3.4.7
-
cpe:2.3:a:invisioncommunity:invision_power_board:3.4.8
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.0.0
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.0.1
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.0.10.2
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.0.11
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.0.12.1
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.0.13.1
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.0.2
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.0.3
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.0.4
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.0.5.1
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.0.6.1
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.0.7
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.0.8
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.0.8.1
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.0.9.2
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.1.0
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.1.1
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.1.2
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.1.3.1
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.1.3.2
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.1.4.1
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.1.5
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.1.5.1
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.1.5.2
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.1.6
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.1.6.1
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.1.7
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.1.8
-
cpe:2.3:a:invisioncommunity:invision_power_board:4.1.8.1