PT-2008-4949 · Pligg+1 · Pligg+1
Published
2008-08-10
·
Updated
2017-08-08
·
CVE-2008-3573
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Pligg version 9.9.5
Francisco Burzi PHP-Nuke version 8.1
Description
The issue concerns the CAPTCHA implementation, which provides a critical random number,
ts random, within the URL in the SRC attribute of an IMG element. This allows remote attackers to bypass the CAPTCHA test by calculating a value that combines ts random with the current date and the HTTP User-Agent string.Recommendations
For Pligg version 9.9.5, consider modifying the CAPTCHA implementation to avoid exposing the
ts random value in the URL.
For Francisco Burzi PHP-Nuke version 8.1, restrict access to the CAPTCHA functionality until a secure implementation is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Php-Nuke
Pligg