Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-2918

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2006-2918
Last Modified 20 Jun 2011 12:00:00
Published 23 Jun 2006 05:06:00
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2006-2918

Summary

The Lanap BotDetect APS.NET CAPTCHA component before 1.5.4.0 stores the UUID and hash for a CAPTCHA in the ViewState of a page, which makes it easier for remote attackers to conduct automated attacks by "replaying the ViewState for a known number."

Vulnerable Systems

Application

  • Lanap Botdetect Captcha Asp.net


References

BID - 18315

BUGTRAQ - 20060622 SYMSA-2006-005

XF - lanap-botdetect-captcha-security-bypass(27409)

VUPEN - ADV-2006-2518

CONFIRM - http://www.symantec.com/enterprise/research/SYMSA-2006-005.txt

SECTRACK - 1016371

SREASON - 1139

SECUNIA - 20830


Last Updated: 27 May 2016 10:42:48