CVE-2007-2999 - CERT CVE
ID CVE-2007-2999
Sažetak Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers to determine valid Active Directory account names.
Reference
CVSS
Base: 1.8
Impact: 2.9
Exploitability:3.2
Pristup
VektorSloženostAutentikacija
ADJACENT_NETWORK HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL NONE NONE
CVSS vektor AV:A/AC:H/Au:N/C:P/I:N/A:N
Zadnje važnije ažuriranje 06-11-2012 - 03:40
Objavljeno 04-06-2007 - 17:30