CVE-2002-1416

The POP3 service for WebEasyMail 3.4.2.2 and earlier generates diffferent error messages for valid and invalid usernames during authentication, which makes it easier for remote attackers to conduct brute force attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:webeasymail:webeasymail:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:41

Type Values Removed Values Added
References () http://online.securityfocus.com/archive/1/288222 - Exploit, Vendor Advisory () http://online.securityfocus.com/archive/1/288222 - Exploit, Vendor Advisory
References () http://www.iss.net/security_center/static/9925.php - Vendor Advisory () http://www.iss.net/security_center/static/9925.php - Vendor Advisory
References () http://www.securityfocus.com/bid/5519 - Vendor Advisory () http://www.securityfocus.com/bid/5519 - Vendor Advisory

Information

Published : 2003-04-11 04:00

Updated : 2025-04-03 01:03


NVD link : CVE-2002-1416

Mitre link : CVE-2002-1416

CVE.ORG link : CVE-2002-1416


JSON object : View

Products Affected

webeasymail

  • webeasymail