Sploitus

CVE-2008-5112

1 known exploit for CVE-2008-5112

The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 responds differently to a failed bind attempt depending on whether the user account exists and is permitted to login, which allows remote attackers to enumerate valid usernames via a series of LDAP bind requests, as demonstrated by ldapuserenum.

Microsoft Windows
= server_2003
Microsoft Windows 2000
All versions
Fix
Available
CVSS 2.0
5.0 MEDIUM
EPSS
17.6% (97th percentile)
Weakness
CWE-200
NVD status
Modified
Published
2008-11-17
CVE-2008-5112 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2008-5112

Proof-of-concept code and exploit modules indexed by Sploitus