CVE-2002-2410
openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different resp
openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks and obtain certain configuration and version information.
MEDIUM · CVSS 5
EPSS 0.00419
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0