AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote attackers to determine the existence of valid account numbers via a brute force attack.
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Link | Tags |
---|---|
http://www.iss.net/security_center/static/7185.php | vdb entry broken link |
http://www.securityfocus.com/bid/3371 | exploit vdb entry third party advisory broken link |
http://archives.neohapsis.com/archives/bugtraq/2001-09/0235.html | mailing list broken link vendor advisory |