SIPS 0.2.2 - User Information Disclosure

EDB-ID:

22381

Author:

dwcgr0up

Type:

remote

Platform:

Multiple

Published:

2003-03-18

source: http://www.securityfocus.com/bid/7134/info

It has been reported that authentication is not required to view user account information. As a result, an unauthorized remote attacker may be able to view potentially sensitive information. This may aid in launching further attacks against a target user or system.

http://www.example.com/[sips_directory]/sipssys/users/[first_letter_of_UserID]/