Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2004-1602 | First vendor Publication | 2004-10-15 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1602 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-203 | Information Exposure Through Discrepancy |
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2005-11-03 | Name : proftpd < 1.2.11 remote user enumeration File : nvt/proftpd_user_enum.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
10758 | ProFTPD Login Timing Account Name Enumeration ProFTPD contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when an attacker measures the elapsed time between the sending of the 'USER' command to the server and the servers response, which will disclose which user accounts are valid resulting in a loss of confidentiality. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2004-10-17 | Name : The remote FTP server may disclose the list of valid usernames. File : proftpd_user_enum.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:22:55 |
|
2024-11-28 12:06:23 |
|
2024-02-15 21:28:26 |
|
2021-05-04 12:02:32 |
|
2021-04-22 01:02:44 |
|
2020-05-23 00:16:02 |
|
2017-07-11 12:01:38 |
|
2016-10-18 12:01:27 |
|
2014-02-17 10:28:58 |
|
2013-05-11 11:45:26 |
|