PT-2007-4586 · Simple Machines · Simple Machines Forum

Published

2007-06-21

·

Updated

2018-10-16

·

CVE-2007-3308

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Simple Machines Forum (SMF) version 1.1.2
Description The issue concerns a concatenation method used in creating a WAV file CAPTCHA, which lacks sufficient randomization. This weakness allows remote attackers to bypass the CAPTCHA test using automated brute-force attacks.
Recommendations For Simple Machines Forum (SMF) version 1.1.2, consider implementing additional security measures to enhance CAPTCHA randomness and prevent brute-force attacks, such as increasing the complexity of the CAPTCHA or limiting the number of attempts allowed.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3308

Affected Products

Simple Machines Forum