JCaptcha Sound File CAPTCHA Security Bypass Vulnerability
BID:39643
Info
JCaptcha Sound File CAPTCHA Security Bypass Vulnerability
| Bugtraq ID: | 39643 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 22 2010 12:00AM |
| Updated: | Jan 05 2011 09:12PM |
| Credit: | Hugo Vazquez |
| Vulnerable: |
JCaptcha JCaptcha 1.0 |
| Not Vulnerable: |
JCaptcha JCaptcha 2.0-alpha2 |
Discussion
JCaptcha Sound File CAPTCHA Security Bypass Vulnerability
JCaptcha is prone to a security-bypass vulnerability.
Successfully exploiting this issue may allow attackers to perform automated attacks on the affected application.
JCaptcha is prone to a security-bypass vulnerability.
Successfully exploiting this issue may allow attackers to perform automated attacks on the affected application.
Exploit / POC
JCaptcha Sound File CAPTCHA Security Bypass Vulnerability
An attacker can use readily available utilities.
An attacker can use readily available utilities.
Solution / Fix
JCaptcha Sound File CAPTCHA Security Bypass Vulnerability
Solution:
Updates are available to address this issue. Please see the references for more information.
Solution:
Updates are available to address this issue. Please see the references for more information.
References
JCaptcha Sound File CAPTCHA Security Bypass Vulnerability
References:
References:
- JCaptcha 2.0-alpha-2 Alpha-2 Release Notes (JCaptcha)
- Possible vulnerability in JCAPTCHA (Hugo Vazquez)
- Vendor Homepage (JCaptcha)