vendor:
FTPShell server
by:
albalawi_sultan
7.5
CVSS
HIGH
Denial of Service
20
CWE
Product Name: FTPShell server
Affected Version From: 6.36
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7
Exploit FTPShell server 6.36 ‘.csv’ Crash(PoC)
This exploit causes a crash in FTPShell server 6.36 when importing a CSV file. The exploit payload is a series of characters in a specific format that triggers the crash. It has been tested on Windows 7. The exploit can be found at http://www.ftpshell.com/download.htm.
Mitigation:
The vendor has not provided a patch or mitigation for this vulnerability. It is recommended to avoid importing CSV files from untrusted sources.