The login for Hosting Controller 1.1 through 1.4.1 returns different error messages when a valid or invalid user is provided, which allows remote attackers to determine the existence of valid usernames and makes it easier to conduct a brute force attack.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2002-05-03T04:00:00

Updated: 2024-08-08T02:42:28.334Z

Reserved: 2002-05-01T00:00:00

Link: CVE-2002-0212

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2002-05-16T04:00:00.000

Modified: 2016-10-18T02:17:10.743

Link: CVE-2002-0212

cve-icon Redhat

No data.