The Lanap BotDetect APS.NET CAPTCHA component before 1.5.4.0 stores the UUID and hash for a CAPTCHA in the ViewState of a page, which makes it easier for remote attackers to conduct automated attacks by "replaying the ViewState for a known number."
References
Configurations
Information
Published : 2006-06-23 14:06
Updated : 2018-10-18 09:43
NVD link : CVE-2006-2918
Mitre link : CVE-2006-2918
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
lanap_botdetect
- captcha_asp.net