PT-2000-1912 · Stalker · Stalker Communigate Pro

Published

2000-12-11

·

Updated

2017-10-10

·

CVE-2000-1002

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Stalker CommuniGate Pro version 3.3.2
Description The issue allows remote attackers to determine valid email addresses on the server, which can be used for SPAM attacks. This is possible because the POP3 daemon generates different error messages for invalid usernames versus invalid passwords.
Recommendations For Stalker CommuniGate Pro version 3.3.2, consider modifying the POP3 daemon to return generic error messages for both invalid usernames and passwords to prevent attackers from determining valid email addresses. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-1002

Affected Products

Stalker Communigate Pro