Vulnerability Description
Amberdms Billing System (ABS) before 1.4.1 does not properly implement blacklisting after detection of invalid login attempts, which makes it easier for remote attackers to obtain access via a brute-force approach.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amberdms | Amberdms Billing System | <= 1.4.0 |
Related Weaknesses (CWE)
References
- https://projects.jethrocarr.com/p/oss-amberdms-bs/source/tree/f23f1121bd137bf798
- https://raw.github.com/jethrocarr/amberdms-bs/master/help/docs/CHANGELOG
- https://projects.jethrocarr.com/p/oss-amberdms-bs/source/tree/f23f1121bd137bf798
- https://raw.github.com/jethrocarr/amberdms-bs/master/help/docs/CHANGELOG
FAQ
What is CVE-2010-5291?
CVE-2010-5291 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Amberdms Billing System (ABS) before 1.4.1 does not properly implement blacklisting after detection of invalid login attempts, which makes it easier for remote attackers to obtain access via a brute-f...
How severe is CVE-2010-5291?
CVE-2010-5291 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-5291?
Check the references section above for vendor advisories and patch information. Affected products include: Amberdms Amberdms Billing System.