vendor:
FileApp
by:
m0ebiusc0de
7,5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: FileApp
Affected Version From: FileApp < v.2.0
Affected Version To: iPad 3.2.2 (jailed)
Patch Exists: NO
Related CWE: N/A
CPE: a:digidna:fileapp
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP PRO SP3
2010
FileApp < 2.0 FTP Denial of Service for iPhone,iPod,iPad
A denial of service vulnerability exists in FileApp < v.2.0, iPad 3.2.2 (jailed) when a malicious user sends a large number of USER and PASS commands to the FTP server. This causes the server to crash and become unresponsive.
Mitigation:
Ensure that the FTP server is configured to limit the number of USER and PASS commands that can be sent in a given period of time.