漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Disclosure of sensitive information in Horde Groupware
Vulnerability Description
Horde Groupware v5.2.22 has a user enumeration vulnerability that allows an unauthenticated attacker to determine the existence of valid accounts on the system. To exploit the vulnerability, an HTTP request must be sent to ‘/imp/attachment.php’ including the parameters ‘id’ and ‘u’. If the specified user exists, the server will return the download of an empty file; if it does not exist, no download will be initiated, which unequivocally reveals the validity of the user.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
信息暴露
Vulnerability Title
Horde Groupware 信息泄露漏洞
Vulnerability Description
Horde Groupware是Horde开源的一个协作软件套件。 Horde Groupware v5.2.22版本存在信息泄露漏洞,该漏洞源于未经验证的攻击者可通过发送HTTP请求确定有效账户是否存在。
CVSS Information
N/A
Vulnerability Type
N/A