ioFTPD 0.5.84 u responds with different messages depending on whether or not a username exists, which allows remote attackers to enumerate valid usernames.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Ioftpd |
Inicom_networks |
5.8.4u (including) |
5.8.4u (including) |
References