CS&T CorporateTime for the Web returns different error messages for invalid usernames and invalid passwords, which allows remote attackers to determine valid usernames on the server.
References
Configurations
Information
Published : 2000-12-11 05:00
Updated : 2017-07-11 01:29
NVD link : CVE-2000-1030
Mitre link : CVE-2000-1030
JSON object : View
Products Affected
csandt
- corporatetime_for_the_web
CWE
