Security Advisory
CVE-2008-1166
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Flyspray 0.9.9.4 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames.