Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 responds differently to a failed bind attempt depending on whether the user account exists and is permitted to login, which allows remote attackers to enumerate valid usernames via a series of LDAP bind requests, as demonstrated by ldapuserenum.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Microsoft活动目录LDAP服务器用户名枚举漏洞
Vulnerability Description
Microsoft Windows是美国微软(Microsoft)公司发布的一系列操作系统。 Microsoft的LDAP服务器响应用户提供凭据的方式存在信息泄露漏洞。如果提供了无效的口令,服务器会响应结果代码49(invalidCredentials)和错误消息,如果提供了无效的用户名会提供不同的错误消息。 对于已有的用户,bind响应类似于: 80090308: LdapErr: DSID-0C090334, comment: AcceptSecurityContext error, data 52e
CVSS Information
N/A
Vulnerability Type
N/A