5
CVSSv2

CVE-2001-1528

Published: 31/12/2001 Updated: 14/02/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote malicious users to determine the existence of valid account numbers via a brute force attack.

Vulnerable Product Search on Vulmon Subscribe to Product

amtote homebet -

Exploits

source: wwwsecurityfocuscom/bid/3371/info Homebet is an internet based betting application that is developed by Amtote International A vulnerability exists in Homebet which could enable a non-registered user to confirm the validity of possible legitimate users and their PIN numbers ## Amtote brute force thingy @method = 'POST /homebe ...