CVE-2000-1030 Information

Description

CS&T CorporateTime for the Web returns different error messages for invalid usernames and invalid passwords which allows remote attackers to determine valid usernames on the server.

Reference

http://www.securityfocus.com/archive/1/142672 http://www.securityfocus.com/bid/1888 https://exchange.xforce.ibmcloud.com/vulnerabilities/5529

Share on: