vendor:
Core FTP Server
by:
7.5
CVSS
HIGH
Denial of Service
CWE
Product Name: Core FTP Server
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Core FTP Server Version 1.2, build 535, 32-bit – Crash P.O.C.
This script exploits a vulnerability in Core FTP Server version 1.2, build 535, 32-bit, causing it to crash. It takes the host, port, username, and password as command line arguments. The script then attempts to connect to the remote Core FTP Server and authenticate. After sending a first buffer of bad data, it waits for 30 seconds and sends a second buffer of bad data. This causes the server to crash, resulting in a denial of service.