PT-2002-3122 · Open Webmail · Open Webmail

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-2410

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open WebMail versions 1.7 through 1.71
Description The issue allows remote attackers to identify valid usernames via brute force attacks by generating different responses whether a user exists or not. It also reveals sensitive information in error messages and certain configuration and version information.
Recommendations For Open WebMail versions 1.7 through 1.71, consider modifying the error messages to not disclose sensitive information and implement measures to prevent brute force attacks, such as limiting the number of login attempts or introducing a delay between attempts.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2002-2410

Affected Products

Open Webmail