CS&T CorporateTime for the Web returns different error messages for invalid usernames and invalid passwords, which allows remote attackers to determine valid usernames on the server.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Corporatetime_for_the_web |
Csandt |
* |
2.1.2 |
References