Skip to content

Known CVE

ProFTPD 1.2.x - Username Enumeration via Timing Attack

ProFTPD versions 1.2.x (including 1.2.8 and 1.2.10) are vulnerable to timing attacks that allow remote attackers to distinguish valid usernames from invalid ones. The server responds in varying amounts of time when a given username exists, enabling username enumeration through response time analysis.

CVE-2004-1602

Medium2004CVSS 5CWE-203

cve2004 · network · ftp · proftpd · tcp · passive · timing-attack · user-enum

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website