CS&T CorporateTime for the Web returns different error messages for invalid usernames and invalid passwords, which allows remote attackers to determine valid usernames on the server.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2000-1017 | CS&T CorporateTime for the Web returns different error messages for invalid usernames and invalid passwords, which allows remote attackers to determine valid usernames on the server. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T05:37:32.226Z
Reserved: 2000-11-24T00:00:00.000Z
Link: CVE-2000-1030
No data.
Status : Deferred
Published: 2000-12-11T05:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2000-1030
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD