CVE Vulnerabilities

CVE-2004-2313

Published: Dec 31, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Inter7 SqWebMail 3.4.1 through 3.6.1 generates different error messages for incorrect passwords versus correct passwords on non-mail-enabled accounts (such as root), which allows remote attackers to guess the root password via brute force attacks.

Affected Software

Name Vendor Start Version End Version
Sqwebmail Inter7 3.4.1 (including) 3.4.1 (including)
Sqwebmail Inter7 3.5.0 (including) 3.5.0 (including)
Sqwebmail Inter7 3.5.1 (including) 3.5.1 (including)
Sqwebmail Inter7 3.5.2 (including) 3.5.2 (including)
Sqwebmail Inter7 3.5.3 (including) 3.5.3 (including)
Sqwebmail Inter7 3.6.0 (including) 3.6.0 (including)
Sqwebmail Inter7 3.6.1 (including) 3.6.1 (including)

References