peter bassill · operator
$ cve CVE-2001-1528 JSON

CVE-2001-1528 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 7.9% (pctl 95)

Patch early

A public exploit exists.

Description

AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are provided, which allows remote attackers to determine the existence of valid account numbers via a brute force attack.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS7.91% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-203
On CISA KEVno
Public exploityes
Published2001-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
amtotehomebet

Public exploits

SourceTitleDate
exploit-dbAmtote Homebet - Account Information Brute Force2001-09-28

References

→ the Explorer  ·  watch your stack  ·  NVD