vendor:
Filetto
by:
Alvaro J. Gene
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Filetto
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: YES
Related CWE: N/A
CPE: a:utillyty:filetto:1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 SP1
2020
Filetto 1.0 – ‘FEAT’ Denial of Service (PoC)
A denial of service vulnerability exists in Filetto 1.0, which allows an authenticated user to crash the FTP server by sending a specially crafted 'FEAT' command with an overly long string. This could allow an attacker to crash the FTP server, resulting in a denial of service condition.
Mitigation:
Upgrade to the latest version of Filetto, which is not vulnerable to this attack.