vendor:
VicFTPS
by:
Alfons Luja sp Z.0.0
7.5
CVSS
HIGH
Denial of Service (DoS)
400
CWE
Product Name: VicFTPS
Affected Version From: VicFTPS v5.0
Affected Version To: VicFTPS v5.0
Patch Exists: YES
Related CWE: N/A
CPE: a:vicftps:vicftps:5.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2020
VicFTPS v5.0 Remote DoS POC
VicFTPS v5.0 is vulnerable to a remote denial of service attack. An attacker can send a specially crafted LIST command with a long string of 0x42 characters to the FTP server, causing it to crash. This vulnerability was discovered by Alfons Luja sp Z.0.0 in the year 2020.
Mitigation:
Upgrade to the latest version of VicFTPS v5.0 or later.