CVE-2004-1428

ArGoSoft FTP before 1.4.2.1 generates an error message if the user name does not exist instead of prompting for a password, which allows remote attackers to determine valid usernames.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:argosoft:ftp_server:1.4.1.8:*:*:*:*:*:*:*
cpe:2.3:a:argosoft:ftp_server:1.4.1.9:*:*:*:*:*:*:*
cpe:2.3:a:argosoft:ftp_server:1.4.1.3:*:*:*:*:*:*:*
cpe:2.3:a:argosoft:ftp_server:1.4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:argosoft:ftp_server:1.4.1.1:*:*:*:*:*:*:*
cpe:2.3:a:argosoft:ftp_server:1.4.1.2:*:*:*:*:*:*:*
cpe:2.3:a:argosoft:ftp_server:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:argosoft:ftp_server:1.4.2.1:*:*:*:*:*:*:*
cpe:2.3:a:argosoft:ftp_server:1.4.1.5:*:*:*:*:*:*:*
cpe:2.3:a:argosoft:ftp_server:1.4.1.6:*:*:*:*:*:*:*
cpe:2.3:a:argosoft:ftp_server:1.4.1.7:*:*:*:*:*:*:*

Information

Published : 2004-12-31 05:00

Updated : 2017-07-11 01:31


NVD link : CVE-2004-1428

Mitre link : CVE-2004-1428


JSON object : View

Products Affected

argosoft

  • ftp_server