Affected configuration(s):
cpe:/a:visibility_software:cyber_recruiter:6.2
cpe:/a:visibility_software:cyber_recruiter:6.4
cpe:/a:visibility_software:cyber_recruiter:6.6
cpe:/a:visibility_software:cyber_recruiter:6.8
cpe:/a:visibility_software:cyber_recruiter:7.0
cpe:/a:visibility_software:cyber_recruiter:7.2
cpe:/a:visibility_software:cyber_recruiter:8.0
Date published: 2014-02-10T17:55:03.933-05:00
Date last modified: 2014-02-21T00:06:47.750-05:00
CVSS Score: 4.3
Principal attack vector: NETWORK
Complexity: MEDIUM
Reference URL: http://www.securityfocus.com/bid/65564
Summary: The user login page in Visibility Software Cyber Recruiter before 8.1.00 generates different responses for invalid password-retrieval attempts depending on which data elements are incorrect, which might allow remote attackers to obtain account-related information via a series of requests.