PT-2000-1912 · Stalker · Stalker Communigate Pro
Publicado
2000-12-11
·
Atualizado
2017-10-10
·
CVE-2000-1002
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Stalker CommuniGate Pro version 3.3.2
Description
The issue allows remote attackers to determine valid email addresses on the server, which can be used for SPAM attacks. This is possible because the POP3 daemon generates different error messages for invalid usernames versus invalid passwords.
Recommendations
For Stalker CommuniGate Pro version 3.3.2, consider modifying the POP3 daemon to return generic error messages for both invalid usernames and passwords to prevent attackers from determining valid email addresses. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Stalker Communigate Pro