PT-2000-1912 · Stalker · Stalker Communigate Pro
Published
2000-12-11
·
Updated
2017-10-10
·
CVE-2000-1002
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Stalker CommuniGate Pro version 3.3.2
Description
The issue allows remote attackers to determine valid email addresses on the server, which can be used for SPAM attacks. This is possible because the POP3 daemon generates different error messages for invalid usernames versus invalid passwords.
Recommendations
For Stalker CommuniGate Pro version 3.3.2, consider modifying the POP3 daemon to return generic error messages for both invalid usernames and passwords to prevent attackers from determining valid email addresses. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Stalker Communigate Pro