PT-2003-1547 · Blackmoon · Blackmoon Ftp Server

Daniel Nyström

+1

·

Published

2003-05-21

·

Updated

2016-10-18

·

CVE-2003-0343

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: BlackMoon FTP Server version 2.6 Free Edition
Description: The issue allows remote attackers to more easily conduct brute force attacks because the software generates an "Account does not exist" error message when an invalid username is entered.
Recommendations: For version 2.6 Free Edition, consider modifying the error message handling to prevent disclosure of account existence information, or apply alternative security measures to mitigate brute force attacks.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0343

Affected Products

Blackmoon Ftp Server