CVE Database
/

CVE-2008-2020

Back to search

CVE-2008-2020

Published: Apr 30, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) phpMyBitTorrent 1.2.2, (4) TorrentFlux 2.3, (5) e107 0.7.11, (6) WebZE 0.5.9, (7) Open Media Collectors Database (aka OpenDb) 1.5.0b4, and (8) Labgab 1.1 uses a code_bg.jpg background image and the PHP ImageString function in a way that produces an insufficient number of different images, which allows remote attackers to pass the CAPTCHA test via an automated attack using a table of all possible image checksums and their corresponding digit strings.

VendorProductVersions

n/a

n/a

affected
n/a

References

20080419 Deciphering the PHP-Nuke Capthca
mailing-list
x_refsource_BUGTRAQ
3834
third-party-advisory
x_refsource_SREASON
28877
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now