Cyber Recruiter Invalid Login Handling User Enumeration Weakness
BID:65564
Info
Cyber Recruiter Invalid Login Handling User Enumeration Weakness
| Bugtraq ID: | 65564 |
| Class: | Design Error |
| CVE: |
CVE-2014-1931 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 14 2014 12:00AM |
| Updated: | Feb 14 2014 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cyber Recruiter Invalid Login Handling User Enumeration Weakness
Cyber Recruiter is prone to a user-enumeration weakness.
An attacker may leverage this issue to harvest valid usernames, which may aid in further attacks.
Cyber Recruiter 8.0.00 is vulnerable; other versions may also be affected.
Cyber Recruiter is prone to a user-enumeration weakness.
An attacker may leverage this issue to harvest valid usernames, which may aid in further attacks.
Cyber Recruiter 8.0.00 is vulnerable; other versions may also be affected.
Exploit / POC
Cyber Recruiter Invalid Login Handling User Enumeration Weakness
An attacker can exploit this issue by supplying the application with crafted requests.
An attacker can exploit this issue by supplying the application with crafted requests.
Solution / Fix
Cyber Recruiter Invalid Login Handling User Enumeration Weakness
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cyber Recruiter Invalid Login Handling User Enumeration Weakness
References:
References: