ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T01:00:36.524Z
Reserved: 2005-02-20T00:00:00
Link: CVE-2004-1602

No data.

Status : Deferred
Published: 2004-10-15T04:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2004-1602

No data.