vendor:
Dream FTP Server
by:
InTeL
7,5
CVSS
HIGH
Denial of Service
N/A
CWE
Product Name: Dream FTP Server
Affected Version From: 1.0.2
Affected Version To: 1.0.2
Patch Exists: NO
Related CWE: N/A
CPE: a:dream_ftp:dream_ftp_server:1.0.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2
2008
DREAM FTP Server 1.0.2 (PORT) Denial of Service Exploit
Dream FTP v1.02 also has anonymous logins enabled by default which enables anyone to crash the server at will. But if the anonymous logins have been disabled try it with a another user/pass account. The exploit sends an evil buffer of 40 characters to the server, which causes the server to crash.
Mitigation:
Disable anonymous logins and use strong passwords for user accounts.