Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
ArGoSoft FTP before 1.4.2.1 generates an error message if the user name does not exist instead of prompting for a password, which allows remote attackers to determine valid usernames.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ArGoSoft FTP Server泄露合法用户名允许暴力猜解漏洞
Vulnerability Description
ArGoSoft FTP Server是一款轻量级FTP服务程序。 ArGoSoft FTP Server不正确处理验证过程,远程攻击者可以利用这个漏洞获得合法用户名并可能进行暴力猜解。 ArGoSoft FTP Server 1.4.2.1对USER命令处理不充分,提交合法用户名的USER命令会返回正常密码提示符,但如果非法用户名就会返回: 530 User NAME_HERE does not exist 通过这些信息可猜解合法用户名。 另外ArGoSoft FTP Server 1.4.2.4可多次
CVSS Information
N/A
Vulnerability Type
N/A