vendor:
FtpXQ Server
by:
Federico Fazzi
N/A
CVSS
N/A
Denial-of-Service, Unauthorized Access
Unknown
CWE
Product Name: FtpXQ Server
Affected Version From: FtpXQ Server 3.01
Affected Version To: Unknown
Patch Exists: Unknown
Related CWE: Unknown
CPE: Unknown
Platforms Tested:
Unknown
DataWizard FtpXQ Server Multiple Remote Vulnerabilities
The DataWizard FtpXQ Server is prone to multiple remote vulnerabilities. The first vulnerability is a remote denial-of-service issue that occurs when the application fails to perform adequate bounds checks on user-supplied data before copying it to an insufficiently sized buffer. This can be exploited by an attacker to crash the application, denying access to legitimate users. The second vulnerability is due to the application creating two testing accounts by default. An attacker can access these accounts to gain read/write privileges on the server, potentially compromising the affected computer.
Mitigation:
Unknown