Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to obtain user names and other sensitive information via a direct request to (1) usrmgr/userList.asp or (2) usrmgr/userStatusList.asp.
References
Link | Resource |
---|---|
http://osvdb.org/34514 | |
http://secunia.com/advisories/25212 | Patch Vendor Advisory |
http://securityreason.com/securityalert/2689 | |
http://www.sec-consult.com/289.html | Exploit Vendor Advisory |
http://www.securityfocus.com/archive/1/468048/100/0/threaded | |
http://www.vupen.com/english/advisories/2007/1727 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2007-05-11T03:55:00
Updated: 2018-10-16T14:57:01
Reserved: 2007-05-10T00:00:00
Link: CVE-2007-2590
JSON object: View
NVD Information
Status : Modified
Published: 2007-05-11T04:20:00.000
Modified: 2018-10-16T16:44:40.353
Link: CVE-2007-2590
JSON object: View
Redhat Information
No data.
CWE