CVE-2008-7263

pyftpdlib < 0.5.0 - Unauthenticated Brute-Force Attack via Immediate Response

Title source: llm
STIX 2.1

Description

ftpserver.py in pyftpdlib before 0.5.0 does not delay its response after receiving an invalid login attempt, which makes it easier for remote attackers to obtain access via a brute-force attack.

Scores

EPSS 0.0156
EPSS Percentile 72.1%

Details

CWE
CWE-287
Status published
Products (6)
g.rodola/pyftpdlib 0.1
g.rodola/pyftpdlib 0.1.1
g.rodola/pyftpdlib 0.2.0
g.rodola/pyftpdlib 0.3.0
g.rodola/pyftpdlib < 0.4.0
pypi/pyftpdlib 0 - 0.5.0PyPI
Published Oct 19, 2010
Tracked Since Feb 18, 2026