Vulnerability Description
ArGoSoft FTP before 1.4.2.1 generates an error message if the user name does not exist instead of prompting for a password, which allows remote attackers to determine valid usernames.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Argosoft | Ftp Server | < 1.4.2.1 |
Related Weaknesses (CWE)
References
- http://marc.info/?l=bugtraq&m=110451582011666&w=2Third Party Advisory
- http://secunia.com/advisories/13063Broken Link
- http://securitytracker.com/id?1012744Broken LinkThird Party AdvisoryVDB Entry
- http://www.argosoft.com/ftpserver/changelist.aspxBroken Link
- http://www.lovebug.org/argosoft_advisory.txtBroken LinkURL Repurposed
- http://www.osvdb.org/11335Broken Link
- http://www.securityfocus.com/bid/12139Broken LinkThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18721Third Party AdvisoryVDB Entry
- http://marc.info/?l=bugtraq&m=110451582011666&w=2Third Party Advisory
- http://secunia.com/advisories/13063Broken Link
- http://securitytracker.com/id?1012744Broken LinkThird Party AdvisoryVDB Entry
- http://www.argosoft.com/ftpserver/changelist.aspxBroken Link
- http://www.lovebug.org/argosoft_advisory.txtBroken LinkURL Repurposed
- http://www.osvdb.org/11335Broken Link
- http://www.securityfocus.com/bid/12139Broken LinkThird Party AdvisoryVDB Entry
FAQ
What is CVE-2004-1428?
CVE-2004-1428 is a vulnerability with a CVSS score of 5.0 (MEDIUM). ArGoSoft FTP before 1.4.2.1 generates an error message if the user name does not exist instead of prompting for a password, which allows remote attackers to determine valid usernames.
How severe is CVE-2004-1428?
CVE-2004-1428 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-1428?
Check the references section above for vendor advisories and patch information. Affected products include: Argosoft Ftp Server.