PunBB uses a predictable cookie_seed value that can be derived from the time of registration of the superadmin account (installation time), which might allow local users to perform unauthorized actions.Referenceshttp://securitytracker.com/id?1017131http://www.securityfocus.com/archive/1/450055/100/0/threadedhttp://www.osvdb.org/30134http://www.wargan.org/index.php/2006/10/29/4-punbb-1213-multiple-vulnerabilities