vendor:
iPhone4 FTP Server
by:
offsetIntruder
7.5
CVSS
HIGH
Remote Crash
N/A
CWE
Product Name: iPhone4 FTP Server
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: N/A
CPE: a:zhang_boyang:iphone4_ftp_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: iPhone4 IOS 4.3.2
2011
iPhone4 FTP Server V1.0 – Empty CWD-RETR Remote Crash
The vulnerability exists in the iPhone4 FTP Server V1.0 application, which allows an attacker to remotely crash the application by sending an empty CWD command. This can be exploited by sending an empty CWD command to the FTP server running on port 2121.
Mitigation:
No known mitigation or remediation for this vulnerability.