Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Exce

Researcher fromTelhack 026 Inc.
#27712of 53,611
9.2Total CVSS
Vulnerabilities · 2
Medium
2
PT-2003-1547
4.6
2003-05-21
Blackmoon · Blackmoon Ftp Server · CVE-2003-0343
Name of the Vulnerable Software and Affected Versions: BlackMoon FTP Server version 2.6 Free Edition Description: The issue allows remote attackers to more easily conduct brute force attacks because the software generates an "Account does not exist" error message when an invalid username is entered. Recommendations: For version 2.6 Free Edition, consider modifying the error message handling to prevent disclosure of account existence information, or apply alternative security measures to mitigate brute force attacks.
PT-2003-1546
4.6
2003-05-20
Blackmoon · Blackmoon Ftp Server · CVE-2003-0342
Name of the Vulnerable Software and Affected Versions: BlackMoon FTP Server version 2.6 Free Edition Description: The issue allows local users to gain privileges by accessing user names and passwords stored in plaintext in the blackmoon.mdb file. Recommendations: For BlackMoon FTP Server version 2.6 Free Edition, consider restricting access to the blackmoon.mdb file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.