Synopsis
The remote mail server is affected by an account enumeration vulnerability.
Description
The remote server appears to be running a version of Qpopper that is older than 4.0.6.
Versions older than 4.0.6 are vulnerable to a bug where remote attackers can enumerate valid usernames based on server responses during the authentication process.
Solution
There is no known solution at this time.
Plugin Details
File Name: qpopper_user_disclosure.nasl
Supported Sensors: Nessus
Vulnerability Information
Exploit Ease: No exploit is required
Vulnerability Publication Date: 6/18/2003
Reference Information
BID: 7110