vendor:
Core FTP Lite
by:
Berat Isler
5.5
CVSS
MEDIUM
Denial of Service
400
CWE
Product Name: Core FTP Lite
Affected Version From: 1.3
Affected Version To: 1.3cBuild1437
Patch Exists: NO
Related CWE:
CPE: a:coreftp:core_ftp:1.3
Platforms Tested: Windows 7 32-bit
2020
Core FTP Lite 1.3 – Denial of Service (PoC)
The exploit script generates a payload and creates a file named "mi.txt" with the payload content. When this payload is pasted into the "username" field of the Core FTP application, it causes the application to crash.
Mitigation:
Apply vendor patches or updates to fix the vulnerability. Avoid using untrusted input.