CVE-2002-2410: Infoleak
openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks and obtain certain configuration and version information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2410?
CVE-2002-2410 is considered a medium severity vulnerability as it allows attackers to enumerate valid usernames.
How do I fix CVE-2002-2410?
To fix CVE-2002-2410, update to a patched version of Open WebMail that addresses this information disclosure issue.
What software is affected by CVE-2002-2410?
CVE-2002-2410 affects Open WebMail versions 1.7 and 1.71.
What type of vulnerability is CVE-2002-2410?
CVE-2002-2410 is an information disclosure vulnerability that reveals sensitive data through error messages.
What can attackers do with CVE-2002-2410?
Attackers can use CVE-2002-2410 to perform brute force attacks to identify valid usernames, leading to potential unauthorized access.