vendor:
FTP Server
by:
Balazs Makany
7,5
CVSS
HIGH
Denial of Service (DoS)
400
CWE
Product Name: FTP Server
Affected Version From: 1.10
Affected Version To: 1.10
Patch Exists: NO
Related CWE: N/A
CPE: a:typsoft:ftp_server:1.10
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2012
Typsoft FTP Server DoS CWD command
This exploit is a Denial of Service (DoS) attack against the Typsoft FTP Server. The exploit sends a malformed CWD command with a string of 250 '.' characters, which causes the server to crash. The exploit requires a valid username and password to execute.
Mitigation:
Disable anonymous access to the FTP server and ensure that all user accounts have strong passwords.