The POP3 service for WebEasyMail 3.4.2.2 and earlier generates diffferent error messages for valid and invalid usernames during authentication, which makes it easier for remote attackers to conduct brute force attacks.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2003-03-18T05:00:00

Updated: 2024-08-08T03:26:27.339Z

Reserved: 2003-02-05T00:00:00

Link: CVE-2002-1416

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2003-04-11T04:00:00.000

Modified: 2008-09-05T20:30:32.733

Link: CVE-2002-1416

cve-icon Redhat

No data.