Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-46v6-92ch-v3xp

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks and obtain certain configuration and version information.

openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks and obtain certain configuration and version information.

EPSS

Процентиль: 61%
0.00419
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
около 23 лет назад

openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks and obtain certain configuration and version information.

EPSS

Процентиль: 61%
0.00419
Низкий

Дефекты

CWE-200