vendor:
ProFTPD
by:
Leon Juranic
4
CVSS
MEDIUM
Code Execution Time Analysis
209
CWE
Product Name: ProFTPD
Affected Version From: 1.2.10
Affected Version To: 1.2.10
Patch Exists: NO
Related CWE:
CPE: a:proftpd:proftpd:1.2.10
Platforms Tested:
ProFTPD Remote User Discovery
An attacker can determine valid, special, and non-existent user names on a remote ProFTPD server by measuring the time delay in the code execution path. This can be done by sending a 'USER' command and measuring the elapsed time between the command and the server response.
Mitigation:
Upgrade to a version of ProFTPD that is not vulnerable. Apply any patches or security updates provided by the vendor.