CVE-2000-1002

Executive Summary

The POP3 daemon in Stalker CommuniGate Pro 3.3.2 leaks whether a username or password is invalid through distinct error messages. This allows remote attackers to enumerate valid email addresses on the server, facilitating targeted spam campaigns. The vulnerability is not listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 5.0 (MEDIUM) - Published: 2000-12-11T05:00:00.000 - Last Modified: 2026-09-23T13:10:00.153

Original Description: POP3 daemon in Stalker CommuniGate Pro 3.3.2 generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to determine valid email addresses on the server for SPAM attacks.

"Those who are free of resentful thoughts surely find peace."

— Buddha
Source: NVD