CVE-2002-2410

openwebmail.pl in Open WebMail 1.7 and 1.71 reveals sensitive information in error messages and generates different responses whether a user exists or not, which allows remote attackers to identify valid usernames via brute force attacks and obtain certain configuration and version information.

Scoring

CVSS base score
0.02
EPSS probability
0.42%
Published
2007-11-01
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs