Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:51996
Category:FTP
Title:ProFTPD Authentication Delay Username Enumeration
Summary:NOSUMMARY
Description:Description:

The remote FTP server according to its version number,
is a ProFTPD server vulnerable to an timing based
enumeration attack. An attacker may, by timing how
long it takes for a login to succeed or fail, determine
whether or not the user exists on the remote system.

Versions up to and including 1.2.10 are vulnerable.

Solution : Upgrade to a later version.

Risk factor : Medium

Cross-Ref: BugTraq ID: 11430
Common Vulnerability Exposure (CVE) ID: CVE-2004-1602
http://www.securityfocus.com/bid/11430
Bugtraq: 20041015 ProFTPD 1.2.x remote users enumeration bug (Google Search)
http://marc.info/?l=bugtraq&m=109786760926133&w=2
http://security.lss.hr/index.php?page=details&ID=LSS-2004-10-02
http://securitytracker.com/id?1011687
XForce ISS Database: proftpd-info-disclosure(17724)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17724
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.