PT-2007-4586 · Simple Machines · Simple Machines Forum
Published
2007-06-21
·
Updated
2018-10-16
·
CVE-2007-3308
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Simple Machines Forum (SMF) version 1.1.2
Description
The issue concerns a concatenation method used in creating a WAV file CAPTCHA, which lacks sufficient randomization. This weakness allows remote attackers to bypass the CAPTCHA test using automated brute-force attacks.
Recommendations
For Simple Machines Forum (SMF) version 1.1.2, consider implementing additional security measures to enhance CAPTCHA randomness and prevent brute-force attacks, such as increasing the complexity of the CAPTCHA or limiting the number of attempts allowed.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Simple Machines Forum