CVE-2004-1602
medium · 5A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response.
5
CVSS
30.7%
EPSS (exploit prob.)
98th
EPSS percentile
2004-10-15
Published
AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
CWE-203
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| proftpd | proftpd | >= 1.2.0, <= 1.2.10 |
Check a specific version with /api/v1/cve/match.
References
- http://marc.info/?l=bugtraq&m=109786760926133&w=2
- http://security.lss.hr/index.php?page=details&ID=LSS-2004-10-02
- http://securitytracker.com/id?1011687
- http://www.securityfocus.com/bid/11430
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17724
- http://marc.info/?l=bugtraq&m=109786760926133&w=2
- http://security.lss.hr/index.php?page=details&ID=LSS-2004-10-02
- http://securitytracker.com/id?1011687
- http://www.securityfocus.com/bid/11430
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17724
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2004-1602