Vulnerabilities > CVE-2008-3573 - Numeric Errors vulnerability in multiple products

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
php-nuke
pligg
CWE-189
exploit available

Summary

The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the ts_random value) within the URL in the SRC attribute of an IMG element, which allows remote attackers to pass the CAPTCHA test via a calculation that combines this value with the current date and the HTTP User-Agent string.

Vulnerable Configurations

Part Description Count
Application
Php-Nuke
1
Application
Pligg
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionPligg 9.9.5 'CAPTCHA' Registration Automation Security Bypass Weakness. CVE-2008-3573. Webapps exploit for php platform
idEDB-ID:32142
last seen2016-02-03
modified2008-08-02
published2008-08-02
reporterMicheal Brooks
sourcehttps://www.exploit-db.com/download/32142/
titlePligg 9.9.5 - 'CAPTCHA' Registration Automation Security Bypass Weakness