Back to search
CVE-2002-2014
Published: Jul 14, 2005
Modified: Sep 17, 2024
PUBLISHED
Description
Lotus Domino 5.0.8 web server returns different error messages when a valid or invalid user is provided in HTTP requests, which allows remote attackers to determine valid user names and makes it easier to conduct brute force attacks.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
3991
vdb-entry
x_refsource_BID
20020131 Script for find domino
mailing-list
x_refsource_BUGTRAQ
20020130 Enumerating users on a Domino webserver
mailing-list
x_refsource_VULN-DEV
lotus-domino-username-disclosure(8038)
vdb-entry
x_refsource_XF
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now