The remote ProFTPd server is as old or older than 1.2.10 It is possible to determine which user names are valid on the remote host based on timing analysis attack of the login procedure. An attacker may use this flaw to set up a list of valid usernames for a more efficient brute-force attack against the remote host.
Upgrade to a newer version
- vsftpd '__tzfile_read()' Function Heap Based Buffer Overflow Vulnerability
- Titan FTP Server Multiple Directory Traversal Vulnerabilities
- Ipswitch WS_FTP Professional 'HTTP' Response Format String Vulnerability
- Serv-U File Server User Directory Information Disclosure Vulnerability
- Femitter FTP Server Multiple Directory Traversal Vulnerabilities