PT-2003-1547 · Blackmoon · Blackmoon Ftp Server
Daniel Nyström
+1
·
Published
2003-05-21
·
Updated
2016-10-18
·
CVE-2003-0343
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
BlackMoon FTP Server version 2.6 Free Edition
Description:
The issue allows remote attackers to more easily conduct brute force attacks because the software generates an "Account does not exist" error message when an invalid username is entered.
Recommendations:
For version 2.6 Free Edition, consider modifying the error message handling to prevent disclosure of account existence information, or apply alternative security measures to mitigate brute force attacks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Blackmoon Ftp Server