Dispatch.cgi/_user/uservCard/ in SiteScape Forum 7.2 and possibly earlier generates different responses in a way that allows remote attackers to enumerate valid usernames.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Sitescape_forum |
Sitescape |
7.2 (including) |
7.2 (including) |
References