PT-2006-2640 · Intracom · Interact
Published
2006-04-06
·
Updated
2017-07-20
·
CVE-2006-1644
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Interact version 2.1.1
Description:
The issue allows remote attackers to determine valid usernames by generating different responses depending on whether or not a username is valid. This is related to the login.php file.
Recommendations:
For Interact version 2.1.1, consider modifying the login.php file to return uniform responses for all username inputs to prevent attackers from determining valid usernames.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Interact