5
CVSSv2

CVE-2013-6043

Published: 27/12/2014 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The login function in Softaculous Webuzo prior to 2.1.4 provides different error messages for invalid authentication attempts depending on whether the user account exists, which allows remote malicious users to enumerate usernames via a series of requests.

Vulnerable Product Search on Vulmon Subscribe to Product

softaculous webuzo

softaculous webuzo 2.1.1

softaculous webuzo 2.1.0

softaculous webuzo 2.1.2

Exploits

# Exploit Title: Webuzo Multiple Vulnerabilities # Date: 7 October 2013 # Exploit Author: Mahendra # Vendor Homepage: wwwwebuzocom # Software Link: downloadswebuzocom/vaphp # Version: 213, other version might be vulnerable # Tested on: CentOS release 62 (FINAL) # CVE : CVE-2013-6041, CVE-2013-6042, CVE-2013-6043 ------------------- ...