5
CVSSv2

CVE-2009-1803

Published: 28/05/2009 Updated: 10/12/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, generates different error messages for a failed login attempt depending on whether the user account exists, which allows remote malicious users to enumerate valid usernames.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freepbx freepbx 2.5.0rc2

freepbx freepbx 2.5.0_beta1

sangoma freepbx 2.5.0

freepbx freepbx 2.5

freepbx freepbx 2.4.1

freepbx freepbx 2.5.2

freepbx freepbx 2.5.0rc3

freepbx freepbx 2.4.0_beta1

freepbx freepbx 2.4

freepbx freepbx 2.5.1

freepbx freepbx 2.4.0_beta2

sangoma freepbx 2.4.0