CVE-2004-1428
CVE-2004-1428
ArGoSoft FTP before 1.4.2.1 generates an error message if the user name does not exist instead of prompting for a password, which allows remote attackers to determine valid usernames.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://marc.info/?l=bugtraq&m=110451582011666&w=2http://secunia.com/advisories/13063http://securitytracker.com/id?1012744https://exchange.xforce.ibmcloud.com/vulnerabilities/18721http://www.argosoft.com/ftpserver/changelist.aspxhttp://www.lovebug.org/argosoft_advisory.txthttp://www.osvdb.org/11335http://www.securityfocus.com/bid/12139