The Lanap BotDetect APS.NET CAPTCHA component prior to 1.5.4.0 stores the UUID and hash for a CAPTCHA in the ViewState of a page, which makes it easier for remote malicious users to conduct automated attacks by "replaying the ViewState for a known number."
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
lanap botdetect captcha asp.net |