CVE

Id
23466  
CVE No.
CVE-2007-0109  
Status
Candidate  
Description
wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.  
Phase
Assigned (20070108)  
Votes
None (candidate not yet proposed)  
Comments