Lotus Domino Username Enumeration Vulnerability
BID:3991
Info
Lotus Domino Username Enumeration Vulnerability
| Bugtraq ID: | 3991 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2002 12:00AM |
| Updated: | Jan 30 2002 12:00AM |
| Credit: | Discovered and posted to Bugtraq by [email protected]. |
| Vulnerable: |
Lotus Domino 5.0.8 |
| Not Vulnerable: | |
Discussion
Lotus Domino Username Enumeration Vulnerability
Lotus Domino Server is an application framework for web based collaborative software. It runs on multiple platforms including Windows and Unix.
An issue has been reported in Lotus Domino server, which could allow for remote users to determine the validity of a username existing on a host.
When a remote user submits a GET request for a possible user's account, the server response will assist the user in determining the validity of the username submitted.
Reportedly, the server will return a HTTP 200 OK message when given a valid user name. If the username is not valid a 404 File not Found error message will be returned.
Lotus Domino Server is an application framework for web based collaborative software. It runs on multiple platforms including Windows and Unix.
An issue has been reported in Lotus Domino server, which could allow for remote users to determine the validity of a username existing on a host.
When a remote user submits a GET request for a possible user's account, the server response will assist the user in determining the validity of the username submitted.
Reportedly, the server will return a HTTP 200 OK message when given a valid user name. If the username is not valid a 404 File not Found error message will be returned.
Exploit / POC
Lotus Domino Username Enumeration Vulnerability
No exploit code required.
No exploit code required.
Solution / Fix
Lotus Domino Username Enumeration Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.