PT-2002-3122 · Open Webmail · Open Webmail

Publicado

2002-12-31

·

Atualizado

2008-09-05

·

CVE-2002-2410

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open WebMail versions 1.7 through 1.71
Description The issue allows remote attackers to identify valid usernames via brute force attacks by generating different responses whether a user exists or not. It also reveals sensitive information in error messages and certain configuration and version information.
Recommendations For Open WebMail versions 1.7 through 1.71, consider modifying the error messages to not disclose sensitive information and implement measures to prevent brute force attacks, such as limiting the number of login attempts or introducing a delay between attempts.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2002-2410

Produtos afetados

Open Webmail