CVE-2008-1166
EUVD-2008-117505.03.2008, 23:44
Flyspray 0.9.9.4 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| flyspray | flyspray | 0.9.9 |
| flyspray | flyspray | 0.9.9.1 |
| flyspray | flyspray | 0.9.9.2 |
| flyspray | flyspray | 0.9.9.3 |
| flyspray | flyspray | 0.9.9.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References