vendor:
Odin Secure FTP Expert
by:
Berat Isler
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Odin Secure FTP Expert
Affected Version From: 7.6.3
Affected Version To: 7.6.3
Patch Exists: Yes
Related CWE: N/A
CPE: a:odin:odin_secure_ftp_expert
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 32-bit
2020
Odin Secure FTP Expert 7.6.3 – Denial of Service (PoC)
A denial of service vulnerability exists in Odin Secure FTP Expert 7.6.3. An attacker can generate a new file with the name 'bune.txt' containing a payload of 6000 'A' characters. When the content of 'bune.txt' is pasted into the 'Quickconnect site' tab of the 'connect' tab in the application, the application will crash.
Mitigation:
Upgrade to the latest version of Odin Secure FTP Expert.