PT-2008-3539 · Simple Machines · Simple Machines Forum

Jessica Hope

·

Publicado

2008-04-30

·

Atualizado

2018-10-11

·

CVE-2008-2019

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Simple Machines Forum (SMF) version 1.1.4
Description The issue allows remote attackers to bypass the CAPTCHA test through an automated attack, considering Hamming distances, due to the reliance on "randomly generated static" to prevent brute-force attacks on the WAV file (audio) CAPTCHA.
Recommendations For Simple Machines Forum (SMF) version 1.1.4, consider implementing additional security measures to strengthen the CAPTCHA system, such as enhancing the randomness of the static generation or using alternative CAPTCHA methods. As a temporary workaround, restrict access to sensitive areas of the forum that rely on the CAPTCHA test to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2019

Produtos afetados

Simple Machines Forum