Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Thinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS (Windows) through the /changePassword URI. By accessing the vector, an attacker can determine if a username exists thanks to the message returned; it can be presented in different languages according to the configuration of VirtualUI. Common users are administrator, admin, guest and krgtbt.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Cybele Software Thinfinity VirtualUI 代码问题漏洞
Vulnerability Description
Cybele Software Thinfinity VirtualUI是美国Cybele Software公司的一款支持将远程Windows应用程序嵌入到标准Web应用程序中,从而可以与Javascript编程进行双向交互的解决方案。 Thinfinity VirtualUI 中存在代码问题漏洞,该漏洞源于产品未对changePassword链接的返回信息进行有效处理。攻击者可通过该漏洞枚举获得用户名。以下产品及版本受到影响:Thinfinity VirtualUI 3.0 之前版本。
CVSS Information
N/A
Vulnerability Type
N/A