5

CVE-2004-2313

Inter7 SqWebMail 3.4.1 through 3.6.1 generates different error messages for incorrect passwords versus correct passwords on non-mail-enabled accounts (such as root), which allows remote attackers to guess the root password via brute force attacks.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Inter7Sqwebmail Version3.4.1
Inter7Sqwebmail Version3.5.0
Inter7Sqwebmail Version3.5.1
Inter7Sqwebmail Version3.5.2
Inter7Sqwebmail Version3.5.3
Inter7Sqwebmail Version3.6.0
Inter7Sqwebmail Version3.6.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.541
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N