Loading
The password reset feature in Movable Type before 3.2 generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.
Use Six Apart vendor hub and Movable Type product page to widen CVE-2005-3101 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2007-0231, CVE-2009-2481 and CVE-2011-2676 for nearby disclosures in the same product family.