CVE-2013-6043
Last modified
CVE-2013-6043 is a vulnerability of currently unknown severity. The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of requests.. EPSS estimates a 2.89% chance of exploitation in the next 30 days.
Description
The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of requests.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Softaculous | Webuzo | <= 2.1.3 |
| Softaculous | Webuzo | 2.1.0 |
| Softaculous | Webuzo | 2.1.1 |
| Softaculous | Webuzo | 2.1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-6043?
How severe is CVE-2013-6043?
How do I fix CVE-2013-6043?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-6037Cross-site scripting (XSS) vulnerability in index.php in Ake…
- CVE-2013-6038Stack-based buffer overflow in Trimble SketchUp Viewer 13.0.…
- CVE-2013-6039Multiple cross-site scripting (XSS) vulnerabilities in Nagio…
- CVE-2013-6040MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls before …8.1
- CVE-2013-6041index.php in Softaculous Webuzo before 2.1.4 allows remote a…
- CVE-2013-6042Cross-site scripting (XSS) vulnerability in filemanager/logi…
- CVE-2013-6044The is_safe_url function in utils/http.py in Django 1.4.x be…
- CVE-2013-6045Multiple heap-based buffer overflows in OpenJPEG 1.3 and ear…
- CVE-2013-6047Multiple cross-site scripting (XSS) vulnerabilities in the s…
- CVE-2013-6048The get_group_tree function in lib/Munin/Master/HTMLConfig.p…
- CVE-2013-6049apt-listbugs before 0.1.10 creates temporary files insecurel…
- CVE-2013-6050Integer overflow in Links before 2.8 allows remote attackers…
Are you affected by CVE-2013-6043?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
