5
CVSSv2

CVE-2004-2313

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Inter7 SqWebMail 3.4.1 up to and including 3.6.1 generates different error messages for incorrect passwords versus correct passwords on non-mail-enabled accounts (such as root), which allows remote malicious users to guess the root password via brute force attacks.

Vulnerable Product Search on Vulmon Subscribe to Product

inter7 sqwebmail 3.4.1

inter7 sqwebmail 3.5.2

inter7 sqwebmail 3.5.3

inter7 sqwebmail 3.5.0

inter7 sqwebmail 3.5.1

inter7 sqwebmail 3.6.0

inter7 sqwebmail 3.6.1