vendor:
FTP Server
by:
Beyond Security Ltd.
7.5
CVSS
HIGH
Buffer Overflow, File Enumeration, Denial of Service
119, 22, 400
CWE
Product Name: FTP Server
Affected Version From: 1.4.1.4
Affected Version To: 1.4.1.5
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
Multiple Vulnerabilities in ArGoSoft FTP Server version 1.4 (1.4.1.4)
ArGoSoft FTP Server version 1.4.1.4 is vulnerable to three buffer overruns when handling overly long FTP SITE ZIP and SITE COPY commands, a file enumeration issue involving the SITE UNZIP command and user database corruption denial of service attacks via the SITE PASS command.
Mitigation:
Upgrade to the latest version of ArGoSoft FTP Server (1.4.1.6)