Description
Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack.
Remediation
References
Related Vulnerabilities
WordPress Plugin Side Menu Lite-add sticky fixed buttons SQL Injection (2.2.1)
WordPress Plugin WP-Live Chat by 3CX Cross-Site Scripting (8.0.07)
Oracle HTTP Server CVE-2018-2760 Vulnerability (CVE-2018-2760)
RubyGems Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-0899)