CVE-2007-5404 Information

Description

Layton HelpBox 3.7.1 generates different responses depending on whether or not a username is valid in a failed login attempt which allows remote attackers to enumerate valid usernames.

Reference

http://secunia.com/advisories/27699 http://secunia.com/secunia_research/2007-94/advisory/ http://www.securityfocus.com/bid/27187 https://exchange.xforce.ibmcloud.com/vulnerabilities/39544

Share on: