Synopsis
The remote FTP server is vulnerable by an account-enumeration attack.
Description
It is possible to determine the existence of a user on the remote system by issuing the command CWD ~<username>.
An attacker may use this to determine the existence of known to be vulnerable accounts (like guest) or to determine which system you are running.
Solution
There is no known solution at this time.
Plugin Details
File Name: ftp_check_user.nasl
Supported Sensors: Nessus
Vulnerability Information
Required KB Items: ftp/anonymous