vendor:
Quick 'n EasY Ftp Server
by:
KaGra
7.5
CVSS
HIGH
Denial of Service (D.o.S)
400
CWE
Product Name: Quick 'n EasY Ftp Server
Affected Version From: 2.4
Affected Version To: 2.4
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP1 (English version)
2004
Quick ‘n EasY VER 2.4 Ftp Server remote D.o.S
This exploit allows an attacker to remotely crash the Quick 'n EasY VER 2.4 Ftp Server by sending a large buffer in the PASS command. This can be done without any user account. The vulnerability can be triggered when the server's log file is viewed. The exploit can also be used with other commands like APPE and CWD, but for those, at least a guest account is required. The exploit has been tested on Windows XP SP1 English version.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a newer version of the Quick 'n EasY Ftp Server that addresses this issue. Additionally, limiting access to the log files and implementing proper log file viewing controls can help reduce the impact of this vulnerability.