vendor:
FlashGet
by:
Milad Karimi
7.5
CVSS
HIGH
Denial of Service
119
CWE
Product Name: FlashGet
Affected Version From: 1.9.6
Affected Version To: 1.9.6
Patch Exists: YES
Related CWE: N/A
CPE: a:flashget:flashget:1.9.6
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2020
FlashGet 1.9.6 – Denial of Service (PoC)
A denial of service vulnerability exists in FlashGet 1.9.6. A remote attacker can send a specially crafted FTP request with a long string in the PWD command to cause a buffer overflow, resulting in a denial of service condition. The vulnerability is due to insufficient boundary checks when handling FTP requests. An attacker can send a specially crafted FTP request with a long string in the PWD command to trigger this vulnerability.
Mitigation:
Upgrade to the latest version of FlashGet 1.9.6 or later.