vendor:
GuildFTPd
by:
(x)dmnt
7.5
CVSS
HIGH
Heap Corruption
119
CWE
Product Name: GuildFTPd
Affected Version From: v0.999.8.11
Affected Version To: v0.999.14
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2008
GuildFTPd v0.999.8.11/v0.999.14 heap corruption PoC/DoS exploit
GuildFTPd v0.999.8.11/v0.999.14 is vulnerable to a heap corruption vulnerability. An attacker can send a malicious CWD and LIST command to the server to cause a denial of service. The CWD command contains 124 '/.' characters and the LIST command contains 100 'X' characters. This exploit was published in 2008 by (x)dmnt.
Mitigation:
Upgrade to the latest version of GuildFTPd.