Required CVE Record Information
Description
openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks and obtain certain configuration and version information.
References 3 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- iss.net: open-webmail-information-disclosure(10684) vdb-entryx_transferred
- archives.neohapsis.com: 20021119 Open WebMail 1.71 "background" magic info mailing-listx_transferred
- securityfocus.com: 6232 vdb-entryx_transferred