WebEasyMail POP3 Server Valid User Name Information Disclosure Vulnerability
BID:5519
Info
WebEasyMail POP3 Server Valid User Name Information Disclosure Vulnerability
| Bugtraq ID: | 5519 |
| Class: | Design Error |
| CVE: |
CVE-2002-1416 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 20 2002 12:00AM |
| Updated: | Jul 11 2009 03:56PM |
| Credit: | Discovery of this vulnerability credited to Stan Bubrouski <[email protected]>. |
| Vulnerable: |
WebEasyMail WebEasyMail 3.4.2 .2 |
| Not Vulnerable: | |
Discussion
WebEasyMail POP3 Server Valid User Name Information Disclosure Vulnerability
An issue has been discovered in WebEasyMail's POP3 server which may make it easier for remote attackers to verify the existence of user accounts.
In particular, it is trivial for an attacker to determine if a username exists or not. When a user attempts to authenticate against the POP3 server using an username followed by a password, WebEasyMail returns error messages which distinguish between invalid user names and passwords.
An issue has been discovered in WebEasyMail's POP3 server which may make it easier for remote attackers to verify the existence of user accounts.
In particular, it is trivial for an attacker to determine if a username exists or not. When a user attempts to authenticate against the POP3 server using an username followed by a password, WebEasyMail returns error messages which distinguish between invalid user names and passwords.
Exploit / POC
WebEasyMail POP3 Server Valid User Name Information Disclosure Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
WebEasyMail POP3 Server Valid User Name Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
WebEasyMail POP3 Server Valid User Name Information Disclosure Vulnerability
References:
References:
- WebEasyMail (WebEasyMail)