[Full-disclosure] WebCalendar User Account Enumeration Weakness



WebCalendar is a PHP-based calendar application that can be configured
as a single-user calendar, a multi-user calendar for groups of users,
or as an event calendar viewable by visitors.
See project homepage for details: http://www.k5n.us/webcalendar.php

Description:

The problem is that different error messages are returned depending
on whether an unsuccessful login attempt is performed with a valid or
invalid username in the login page.

Error message extract from 'includes/user.php' can be
"Invalid login"
"Invalid login: incorrect password"
"Invalid login: no such user"

The weakness has been confirmed in version 1.0.1, 1.0.2, 1.0.3.
Other versions may also be affected.


David Maciejak

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • WebCalendar User Account Enumeration Weakness
    ... WebCalendar is a PHP-based calendar application that can be configured ... as a single-user calendar, a multi-user calendar for groups of users, ... The problem is that different error messages are returned depending ... "Invalid login: incorrect password" ...
    (Bugtraq)
  • [Full-disclosure] Re: WebCalendar User Account Enumeration Weakness
    ... According to WebCalendar lead developer, ... as a single-user calendar, a multi-user calendar for groups of users, ... "Invalid login: incorrect password" ... David Maciejak ...
    (Full-Disclosure)
  • Re: WebCalendar User Account Enumeration Weakness
    ... According to WebCalendar lead developer, ... as a single-user calendar, a multi-user calendar for groups of users, ... "Invalid login: incorrect password" ... David Maciejak ...
    (Bugtraq)
  • Re: OWA Calendar Problem
    ... open the item however when you try and save it nothing shows in the calendar. ... There are no error messages that appear. ... If you log onto the same clients mailbox with outlook you are able to create ... appointments without problems, and when you go back into owa, these ...
    (microsoft.public.exchange.admin)
  • RE: HP 4155 ActiveSync "Attention Required"
    ... When I run ActiveSync, Calendar, ... > error messages and dialog boxes that require your input, ... ActiveSync Application is presently allowing full scope. ... > I looked for the log files, outstore.log and whatever the other one ...
    (microsoft.public.pocketpc.activesync)