Multiple Products Forgotten Password Feature CAPTCHA Security Bypass Vulnerability
BID:28877
Info
Multiple Products Forgotten Password Feature CAPTCHA Security Bypass Vulnerability
| Bugtraq ID: | 28877 |
| Class: | Design Error |
| CVE: |
CVE-2008-2020 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 21 2008 12:00AM |
| Updated: | May 07 2015 05:29PM |
| Credit: | Michael Brooks |
| Vulnerable: |
WebZE WebZE 0.5.9 TorrentFlux TorrentFlux 2.3 phpMyBitTorrent phpMyBitTorrent 2.1 PHP-Nuke PHP-Nuke 7.0 PHP-Nuke PHP-Nuke 8.1 OpenDB OpenDB 1.5.0b4 Labgab Project Labgab Project 1.1 e107 e107 website system 0.7.11 123tkShop 123tkShop 0.9.1 |
| Not Vulnerable: | |
Discussion
Multiple Products Forgotten Password Feature CAPTCHA Security Bypass Vulnerability
Multiple products are prone to a security-bypass vulnerability that occurs in the forgotten password feature.
An attacker can exploit this issue to gain access to user passwords of the affected application or perform other automated attacks.
The vulnerability occurs in the following products:
- PHP-Nuke 8.1 FINAL
- PHP Nuke 7.0
- 123tkshop 0.9.1
- phpMyBitTorrent 1.2.2
- torrentflux 2.3
- e107 0.7.11
- webZE 0.5.9
- Labgab Project 1.1
Multiple products are prone to a security-bypass vulnerability that occurs in the forgotten password feature.
An attacker can exploit this issue to gain access to user passwords of the affected application or perform other automated attacks.
The vulnerability occurs in the following products:
- PHP-Nuke 8.1 FINAL
- PHP Nuke 7.0
- 123tkshop 0.9.1
- phpMyBitTorrent 1.2.2
- torrentflux 2.3
- e107 0.7.11
- webZE 0.5.9
- Labgab Project 1.1
Exploit / POC
Multiple Products Forgotten Password Feature CAPTCHA Security Bypass Vulnerability
Attackers can exploit this issue using a browser.
The following exploit code is available:
Attackers can exploit this issue using a browser.
The following exploit code is available:
Solution / Fix
Multiple Products Forgotten Password Feature CAPTCHA Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple Products Forgotten Password Feature CAPTCHA Security Bypass Vulnerability
References:
References:
- e107 Inc. announces new branding and the release of v1.0 (e107)
- Labgab Project Homepage (Labgab)
- my123tkShop e-Commerce-Suite Homepage (my123tkShop e-Commerce-Suite)
- OpenDb Project Page (OpenDb)
- PHP-Nuke Homepage (PHP-Nuke)
- phpMyBitTorrent Homepage (phpMyBitTorrent)
- TorrentFlux Homepage (TorrentFlux)
- WebZE Homepage (WebZE)