vendor:
acFTP
by:
Omnipresent
7,5
CVSS
HIGH
Denial of Service (DoS)
20
CWE
Product Name: acFTP
Affected Version From: 1.4
Affected Version To: 1.4
Patch Exists: YES
Related CWE: N/A
CPE: a:acftp:acftp:1.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2006
acFTP 1.4 DoS Exploit
The vulnerability is caused due to an error within the handling of the argument passed to the 'USER' command. This can be exploited to crash the FTP server via an overly long argument that contains certain character sequences.
Mitigation:
Upgrade to the latest version of acFTP