Mailing List CGatePro@mail.stalker.com Message #100561
From: "Ian Mordey" <ian.mordey@griffin.com>
Subject: Determining valid email addresses via password recovery
Date: Fri, 27 Aug 2010 09:01:15 +0100
To: <cgatepro@mail.stalker.com>

Hi there

It seems it is possible to determine valid email addresses using the password recovery of CGP webmail. If you key in an account name that doesn’t exist you get an error “unknown user account” if you key in a valid account you get a different message “no password recovery email address has been specified”. Are these messages customisable?

 

Thanks

Ian

Subscribe (FEED) Subscribe (DIGEST) Subscribe (INDEX) Unsubscribe Mail to Listmaster