Required CVE Record Information
Description
Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of login requests, possibly related to the Webpac Pro submodule.
References 1 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 1 Total
- securityfocus.com: 20140828 Sierra Library Services Platform Multiple Vulnerability Disclosure mailing-listx_transferred