Auto-Input Protection(AIP) contains a flaw that may allow an attacker too bypass the anti-automated CAPTCHA test. This flaw is triggered when an attacker supplies the same value for the 'ctl00$Main$aip$input' parameter on multiple pages, this may allow the attacker to bypass CAPTCHA testing.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Solution Unknown
Exploit:
Exploit Public
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
Currently, there are no known upgrades or patches to correct this vulnerability. It is possible to temporarily work around the flaw by implementing the workaround suggested in the vendor news post in the references section.