vendor:
SolarFTP
by:
modpr0be
N/A
CVSS
N/A
Denial of Service
N/A
CWE
Product Name: SolarFTP
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: YES
Related CWE: N/A
CPE: //a:solarftp:solarftp:2.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2, Windows XP SP3
2010
SolarFTP 2.0 Multiple Commands Denial of Service Vulnerability
SolarFTP 2.0 will suddenly stop (crash) while these commands were sent: APPE, GET, PUT, NLST, and MDTM. Sending USER with junk also crashing the Admin Configuration but not the service. Stack contains our junk in random. Both EIP and SEH were not overwritten.
Mitigation:
Update to the latest version of SolarFTP 2.0