Vulnerability Details CVE-2002-1416
The POP3 service for WebEasyMail 3.4.2.2 and earlier generates diffferent error messages for valid and invalid usernames during authentication, which makes it easier for remote attackers to conduct brute force attacks.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.018
EPSS Ranking 75.2%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2002-1416
-
cpe:2.3:a:webeasymail:webeasymail:*