CVE-2001-1528

AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote attackers to determine the existence of valid account numbers via a brute force attack.
References
Link Resource
http://archives.neohapsis.com/archives/bugtraq/2001-09/0235.html Broken Link Vendor Advisory
http://www.iss.net/security_center/static/7185.php Broken Link
http://www.securityfocus.com/bid/3371 Broken Link Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:amtote:homebet:-:*:*:*:*:*:*:*

History

14 Feb 2024, 15:17

Type Values Removed Values Added
First Time Amtote
Amtote homebet
CWE NVD-CWE-Other CWE-203
CPE cpe:2.3:a:amtote_international:homebet:*:*:*:*:*:*:*:* cpe:2.3:a:amtote:homebet:-:*:*:*:*:*:*:*
References (BUGTRAQ) http://archives.neohapsis.com/archives/bugtraq/2001-09/0235.html - Vendor Advisory (BUGTRAQ) http://archives.neohapsis.com/archives/bugtraq/2001-09/0235.html - Broken Link, Vendor Advisory
References (BID) http://www.securityfocus.com/bid/3371 - Exploit (BID) http://www.securityfocus.com/bid/3371 - Broken Link, Exploit, Third Party Advisory, VDB Entry
References (XF) http://www.iss.net/security_center/static/7185.php - (XF) http://www.iss.net/security_center/static/7185.php - Broken Link

Information

Published : 2001-12-31 05:00

Updated : 2024-02-28 10:24


NVD link : CVE-2001-1528

Mitre link : CVE-2001-1528

CVE.ORG link : CVE-2001-1528


JSON object : View

Products Affected

amtote

  • homebet
CWE
CWE-203

Observable Discrepancy