Securimage PHP CAPTCHA Security Bypass Vulnerability
BID:47933
Info
Securimage PHP CAPTCHA Security Bypass Vulnerability
| Bugtraq ID: | 47933 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 20 2011 12:00AM |
| Updated: | May 20 2011 12:00AM |
| Credit: | Phil Taylor from Sense of Security Labs. |
| Vulnerable: |
Drew Phillips Securimage 2.0.2 Drew Phillips Securimage 1.0.4 |
| Not Vulnerable: | |
Discussion
Securimage PHP CAPTCHA Security Bypass Vulnerability
Securimage is prone to a security-bypass vulnerability that occurs in its audio version of the CAPTCHA.
Successfully exploiting this issue may allow attackers to perform automated attacks on the affected application.
Securimage versions 1.0.4 through 2.0.2 are vulnerable.
Securimage is prone to a security-bypass vulnerability that occurs in its audio version of the CAPTCHA.
Successfully exploiting this issue may allow attackers to perform automated attacks on the affected application.
Securimage versions 1.0.4 through 2.0.2 are vulnerable.
Exploit / POC
Securimage PHP CAPTCHA Security Bypass Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Securimage PHP CAPTCHA Security Bypass Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Securimage PHP CAPTCHA Security Bypass Vulnerability
References:
References:
- Securimage Homepage (Drew Phillips)
- Sense of Security �?? Security Advisory �?? SOS-11-007. PHPCaptcha / Securimage 2.0. (Sense of Security)