5
CVSSv2

CVE-2004-1602

Published: 15/10/2004 Updated: 15/02/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote malicious users to identify valid usernames by timing the server response.

Vulnerable Product Search on Vulmon Subscribe to Product

proftpd proftpd

Exploits

/* Details Vulnerable Systems: * ProFTPD Version 1210 and below It is possible to determine which user names are valid, which are special, and which ones do not exist on the remote system This can be accomplished by code execution path timing analysis attack at the ProFTPd login procedure There is a very small (but significant) difference in ...