CVE-2008-1166
05.03.2008, 23:44
Flyspray 0.9.9.4 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames.Enginsight
Vendor | Product | Version |
---|---|---|
flyspray | flyspray | 0.9.9 |
flyspray | flyspray | 0.9.9.1 |
flyspray | flyspray | 0.9.9.2 |
flyspray | flyspray | 0.9.9.3 |
flyspray | flyspray | 0.9.9.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References