CVE

Id
10030  
CVE No.
CVE-2004-1602  
Status
Candidate  
Description
ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response.  
Phase
Assigned (20050220)  
Votes
None (candidate not yet proposed)  
Comments