Dispatch.cgi/_user/uservCard/ in SiteScape Forum 7.2 and possibly earlier generates different responses in a way that allows remote attackers to enumerate valid usernames.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sitescape_forum | Sitescape | 7.2 (including) | 7.2 (including) |