Web Application Vulnerability Categorization

"m@d m0nk" <[email protected]> Tue, 1 Apr 2014 07:39:44 +0530
Newsgroups gmane.comp.security.web-applications
Message-ID <CAEbtD=xAEEuAGwAwmruYeJyq6_8NowU9rXAq_AcpLKXnXY2gDw@mail.gmail.com>
Hello Team,

Greetings!!!.

I have a web app with a password recovery option. There is a secret
question and if the user enters the correct answer to the secret
question, the username and password is provided to the user.

If the password recover page / module allows multiple tries
(brute-force and no CAPTCHA or similar mechanism), can we categorize
this vulnerability under "Broken Authentication and Session
Management" or does this fall under any other Vulnerability Category /
OWASP Top 10?

Thanks in advance.

ch33rs,

-- 

__| madm0nk |__
th3 sib3rian m0nk
--------------------------



This list is sponsored by Cenzic
--------------------------------------
Let Us Hack You. Before Hackers Do!
It's Finally Here - The Cenzic Website HealthCheck. FREE.
Request Yours Now! 
http://www.cenzic.com/2009HClaunch_Securityfocus
--------------------------------------