CVE-2005-3101 Information

Description

The password reset feature in Movable Type before 3.2 generates different error messages depending on whether a user exists or not which allows remote attackers to determine valid usernames.

Reference

http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0091.html http://secunia.com/advisories/16899 http://www.securityfocus.com/bid/14911

Share on: