SqWebMail Authentication Response...

- AV AC AU C I A
发布: 2004-01-31
修订: 2025-04-13

SqWebMail leaks sensitive information in authentication responses that may permit aid an attacker in brute forcing the root password on the underlying operating system. The software reportedly issues different responses when the user authenticates successfully as the root user then when a failed attempt occurs. This may provide a covert means of brute-forcing the root password (or possibly other passwords) via the SqWebMail interface.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息