Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2007-0658
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2007-0658

Description:
The (1) Textimage 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal and the (2) Captcha 4.7.x before 4.7-1.2 and 5.x before 5.x-1.1 module for Drupal allow remote attackers to bypass the CAPTCHA test via an empty captcha element in $_SESSION.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/31994
  http://xforce.iss.net/xforce/xfdb/31984

SAID
  Secunia Advisory: SA23983
  Secunia Advisory: SA23985

OSVDB
  32137
  32138

CONFIRM
  http://drupal.org/node/114364
  http://drupal.org/node/114519
  http://cvs.drupal.org/viewcvs/drupal/contributions/modules/textimage/captcha.inc?r1=1.1&r2=1.1.2.1
  http://cvs.drupal.org/viewcvs/drupal/contributions/modules/captcha/captcha.module?r1=1.25.2.1&r2=1.25.2.2

BID
  22329


Return to the previous page.