CVE-2001-1528 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 7.9% (pctl 95)
Patch early
A public exploit exists.
Description
AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote attackers to determine the existence of valid account numbers via a brute force attack.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
| EPSS | 7.91% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-203 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2001-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| amtote | homebet |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Amtote Homebet - Account Information Brute Force | 2001-09-28 |
References
- http://archives.neohapsis.com/archives/bugtraq/2001-09/0235.html
- http://www.iss.net/security_center/static/7185.php
- http://www.securityfocus.com/bid/3371
- http://archives.neohapsis.com/archives/bugtraq/2001-09/0235.html
- http://www.iss.net/security_center/static/7185.php
- http://www.securityfocus.com/bid/3371
→ the Explorer · watch your stack · NVD