vendor:
Ability FTP Server
by:
St0rn
7.5
CVSS
HIGH
Remote Denial of Service
400
CWE
Product Name: Ability FTP Server
Affected Version From: 2.1.2004
Affected Version To: 2.1.2004
Patch Exists: YES
Related CWE: N/A
CPE: a:codecrafters:ability_ftp_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2015
Ability FTP Server afsmain.exe USER Command Remote Dos
Ability FTP Server is vulnerable to a remote denial of service attack. By sending a specially crafted USER command with an overly long argument, an attacker can cause the server to crash. This vulnerability affects Ability FTP Server version 2.1.4 and prior.
Mitigation:
Upgrade to the latest version of Ability FTP Server.