EIP-2026-114740
PRE-CVESolaris 2.6/7.0 - IN.FTPD CWD 'Username' Enumeration
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114740. PoCs published by Johnny Cyberpunk.
AI-analyzed exploit summary This exploit demonstrates an information leakage vulnerability in Solaris ftp daemon (in.ftpd) where remote users can enumerate valid usernames by sending CWD commands with ~username before authentication. The daemon responds differently for valid vs. invalid usernames, allowing account enumeration.
Description
Solaris 2.6/7.0 - IN.FTPD CWD 'Username' Enumeration
Exploits (1)
This exploit demonstrates an information leakage vulnerability in Solaris ftp daemon (in.ftpd) where remote users can enumerate valid usernames by sending CWD commands with ~username before authentication. The daemon responds differently for valid vs. invalid usernames, allowing account enumeration.