PT-2002-3122 · Open Webmail · Open Webmail
Publicado
2002-12-31
·
Atualizado
2008-09-05
·
CVE-2002-2410
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Open WebMail versions 1.7 through 1.71
Description
The issue allows remote attackers to identify valid usernames via brute force attacks by generating different responses whether a user exists or not. It also reveals sensitive information in error messages and certain configuration and version information.
Recommendations
For Open WebMail versions 1.7 through 1.71, consider modifying the error messages to not disclose sensitive information and implement measures to prevent brute force attacks, such as limiting the number of login attempts or introducing a delay between attempts.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Open Webmail