ProFTPD versions 1.2.x (including 1.2.8 and 1.2.10) are vulnerable to timing attacks that allow remote attackers to distinguish valid usernames from invalid ones. The server responds in varying amounts of time when a given username exists, enabling username enumeration through response time analysis.
id: CVE-2004-1602
info:
name: ProFTPD 1.2.x - Username Enumeration via Timing Attack
author: pu
...