MEDIUM · 5.0

CVE-2002-2410

openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists or not, which allows remote attackers to identify va...

Vulnerability Description

openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks and obtain certain configuration and version information.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
Open WebmailOpen Webmail1.7

Related Weaknesses (CWE)

References

FAQ

What is CVE-2002-2410?

CVE-2002-2410 is a vulnerability with a CVSS score of 5.0 (MEDIUM). openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists or not, which allows remote attackers to identify va...

How severe is CVE-2002-2410?

CVE-2002-2410 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-2410?

Check the references section above for vendor advisories and patch information. Affected products include: Open Webmail Open Webmail.