PT-2008-4949 · Pligg+1 · Pligg+1
Publicado
2008-08-10
·
Atualizado
2017-08-08
·
CVE-2008-3573
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Pligg version 9.9.5
Francisco Burzi PHP-Nuke version 8.1
Description
The issue concerns the CAPTCHA implementation, which provides a critical random number,
ts random, within the URL in the SRC attribute of an IMG element. This allows remote attackers to bypass the CAPTCHA test by calculating a value that combines ts random with the current date and the HTTP User-Agent string.Recommendations
For Pligg version 9.9.5, consider modifying the CAPTCHA implementation to avoid exposing the
ts random value in the URL.
For Francisco Burzi PHP-Nuke version 8.1, restrict access to the CAPTCHA functionality until a secure implementation is available.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Php-Nuke
Pligg