vendor:
CesarFTP
by:
zib
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: CesarFTP
Affected Version From: CesarFTP 0.99g
Affected Version To: CesarFTP 0.99g
Patch Exists: NO
Related CWE: N/A
CPE: a:cesarftp:cesarftp:0.99g
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WindowsXP Sp1
2003
CesarFTP 0.99g : CPU Overload
A vulnerability has been reported for CesarFTP. Reportedly, an attacker may crash a target server by supplying excessive data as the argument to the 'CWD' command. This may result in the server hanging, effectively denying service to other legitimate FTP users.
Mitigation:
Limit the size of the argument to the 'CWD' command.