The web login functionality (c/portal/login) in Novell Teaming 1.0 through SP3 (1.0.3) generates different error messages depending on whether the username is valid or invalid, which makes it easier for remote attackers to enumerate usernames.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.sec-consult.com/files/20090415-0-novell-teaming.txt | exploit |
http://www.vupen.com/english/advisories/2009/1048 | vdb entry |
http://secunia.com/advisories/34714 | third party advisory |
http://www.novell.com/support/php/search.do?cmd=displayKC&docType=kc&externalId=7002997&sliceId=1&docTypeID=DT_TID_1_1&dialogID=33090060&stateId=1%200%2033084737 | patch vendor advisory |
http://www.securityfocus.com/archive/1/502704/100/0/threaded | mailing list |
http://www.securitytracker.com/id?1022063 | vdb entry |
http://www.securityfocus.com/bid/34531 | vdb entry exploit |