Open WebMail User Name Information Disclosure Vulnerability
BID:6232
Info
Open WebMail User Name Information Disclosure Vulnerability
| Bugtraq ID: | 6232 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 23 2002 12:00AM |
| Updated: | Nov 23 2002 12:00AM |
| Credit: | Vulnerability discovery credited to "FreeBSDbr Bugtraq DataBase" <[email protected]>. |
| Vulnerable: |
Open Webmail Open Webmail 1.71 Open Webmail Open Webmail 1.7 |
| Not Vulnerable: | |
Discussion
Open WebMail User Name Information Disclosure Vulnerability
Open Webmail is a freely available, open source web email application. It is available for Unix and Linux operating systems.
It has been reported that Open Webmail reveals too much information during the authentication process. When a user enters a user name, Open Webmail returns information indicating the validity of the entered user name. This could allow remote users to gather a list of valid user names through an enumeration attack.
Open Webmail is a freely available, open source web email application. It is available for Unix and Linux operating systems.
It has been reported that Open Webmail reveals too much information during the authentication process. When a user enters a user name, Open Webmail returns information indicating the validity of the entered user name. This could allow remote users to gather a list of valid user names through an enumeration attack.
Exploit / POC
Open WebMail User Name Information Disclosure Vulnerability
This vulnerability may be exploited with a web browser.
This vulnerability may be exploited with a web browser.