vendor:
MiniFTPServer
by:
webmaster442
7.5
CVSS
HIGH
Buffer Corruption Remote Denial Of Service
119
CWE
Product Name: MiniFTPServer
Affected Version From: 1.1.1.0
Affected Version To: 1.1.1.0
Patch Exists: YES
Related CWE: N/A
CPE: miniftpserver
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows XP Professional SP3 (EN)
2020
Mini FTP Server 1.1 Buffer Corruption Remote Denial Of Service Exploit
MiniFTPServer suffers from a denial of service vulnerability when passing large number of bytes after authentication, resulting in a crash. No need for a valid FTP command to exploit this issue.
Mitigation:
Ensure that the FTP server is running the latest version of MiniFTPServer.