First published: Thu Apr 13 2006(Updated: )
Adobe Document Server for Reader Extensions 6.0, during log on, provides different error messages depending on whether the user ID is valid or invalid, which allows remote attackers to more easily identify valid user IDs via brute force attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Document Server | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1788 has been classified with a high severity rating due to the potential for remote attackers to exploit valid user IDs.
To mitigate CVE-2006-1788, ensure that you update to the latest version of Adobe Document Server that addresses this vulnerability.
CVE-2006-1788 allows remote attackers to more easily identify valid user IDs, increasing the risk of unauthorized access.
CVE-2006-1788 specifically affects Adobe Document Server for Reader Extensions version 6.0.
Yes, CVE-2006-1788 can be exploited by unauthenticated users due to the differing error messages that help identify valid user IDs.