CNCVE编号:CNCVE-20000960 CVE编号:CVE-2000-0960 安全级别:中 漏洞中文描述: Netscape Messaging Server 4.15p1中的POP3服务器针对错误用户名和错误口令生成不同的错误消息,这导致远程攻击者能确定系统上的合法用户并获得email地址来滥发邮件。 漏洞英文描述: The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse. 漏洞参考: BUGTRAQ:20001011 Netscape Messaging server 4.15 poor error strings | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97138100426121&w=2 | BID:1787 | URL:http://www.securityfocus.com/bid/1787 | XF:netscape-messaging-email-verify | URL:htt 系统类型:其他 漏洞类型:设计错误