Open Webmail is a freely available, open source web email application. It is available for Unix and Linux operating systems. It has been reported that Open Webmail reveals too much information during the authentication process. When a user enters a user name, Open Webmail returns information indicating the validity of the entered user name. This could allow remote users to gather a list of valid user names through an enumeration attack.
Open Webmail is a freely available, open source web email application. It is available for Unix and Linux operating systems. It has been reported that Open Webmail reveals too much information during the authentication process. When a user enters a user name, Open Webmail returns information indicating the validity of the entered user name. This could allow remote users to gather a list of valid user names through an enumeration attack.