CVE-2013-6043

Softaculous Webuzo < 2.1.3 - Information Disclosure

Title source: rule
STIX 2.1

Description

The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of requests.

Exploits (1)

exploitdb WORKING POC
by Mahendra · textwebappsphp
https://www.exploit-db.com/exploits/31982

Scores

EPSS 0.1173
EPSS Percentile 93.7%

Details

CWE
CWE-200
Status published
Products (4)
softaculous/webuzo 2.1.0
softaculous/webuzo 2.1.1
softaculous/webuzo 2.1.2
softaculous/webuzo < 2.1.3
Published Dec 27, 2014
Tracked Since Feb 18, 2026