ioFTPD 0.5.84 u responds with different messages depending on whether or not a username exists, which allows remote attackers to enumerate valid usernames.
Link | Tags |
---|---|
http://www.security.nnov.ru/Kdocument79.html | vendor advisory |
http://www.securityfocus.com/bid/15253 | vdb entry |
http://www.osvdb.org/22709 | vdb entry |
http://www.critical.lt/?vulnerabilities/119 | vendor advisory |