FloosieTek FTGatePro Mail Server User Enumeration Weakness
BID:8529
Info
FloosieTek FTGatePro Mail Server User Enumeration Weakness
| Bugtraq ID: | 8529 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 02 2003 12:00AM |
| Updated: | Sep 02 2003 12:00AM |
| Credit: | Discovery is credited to Ziv Kamir <[email protected]>. |
| Vulnerable: |
Floosietek FTGatePro 1.22 (1331) |
| Not Vulnerable: | |
Discussion
FloosieTek FTGatePro Mail Server User Enumeration Weakness
FloosieTek FTGatePro Mail Server leaks information that may allow remote attackers to enumerate mail server users. The software is reported to return different responses based on whether or not a username is valid during authentication.
FloosieTek FTGatePro Mail Server leaks information that may allow remote attackers to enumerate mail server users. The software is reported to return different responses based on whether or not a username is valid during authentication.
Exploit / POC
FloosieTek FTGatePro Mail Server User Enumeration Weakness
There is no exploit required.
There is no exploit required.