vendor:
BulletProof FTP Server
by:
Victor Mondragón
7.8
CVSS
HIGH
Denial of Service
400
CWE
Product Name: BulletProof FTP Server
Affected Version From: 2019.0.0.50
Affected Version To: 2019.0.0.50
Patch Exists: YES
Related CWE: N/A
CPE: a:bpftpserver:bulletproof_ftp_server
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Single Language x64 / Windows 7 Service Pack 1 x64
2019
BulletProof FTP Server 2019.0.0.50 – ‘Storage-Path’ Denial of Service (PoC)
A denial of service vulnerability exists in BulletProof FTP Server 2019.0.0.50 when an attacker sends a specially crafted request containing a large amount of data to the 'Storage-Path' parameter. This can cause the application to crash.
Mitigation:
Upgrade to the latest version of BulletProof FTP Server.