Peter's Math Anti-Spam Spinoff plugin for WordPress generates audio CAPTCHA clips by concatenating static audio files without any additional distortion, which allows remote attackers to bypass CAPTCHA protection by reading certain bytes from the generated clip.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/39688 | vdb entry |
http://www.securityfocus.com/bid/27287 | vdb entry exploit |
http://www.securityfocus.com/archive/1/486331/100/200/threaded | mailing list |
http://docs.google.com/View?docid=df36cd52_19xzmkwqcg |