Описание
The web login functionality (c/portal/login) in Novell Teaming 1.0 through SP3 (1.0.3) generates different error messages depending on whether the username is valid or invalid, which makes it easier for remote attackers to enumerate usernames.
Ссылки
- PatchVendor Advisory
- Exploit
- Exploit
- PatchVendor Advisory
- Exploit
- Exploit
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:novell:teaming:1.0:*:*:*:*:*:*:*
cpe:2.3:a:novell:teaming:1.0:sp1:*:*:*:*:*:*
cpe:2.3:a:novell:teaming:1.0:sp2:*:*:*:*:*:*
cpe:2.3:a:novell:teaming:1.0:sp3:*:*:*:*:*:*
cpe:2.3:a:novell:teaming:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:novell:teaming:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:novell:teaming:1.0.3:*:*:*:*:*:*:*
EPSS
Процентиль: 63%
0.00453
Низкий
5 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
github
почти 4 года назад
The web login functionality (c/portal/login) in Novell Teaming 1.0 through SP3 (1.0.3) generates different error messages depending on whether the username is valid or invalid, which makes it easier for remote attackers to enumerate usernames.
EPSS
Процентиль: 63%
0.00453
Низкий
5 Medium
CVSS2
Дефекты
CWE-200