vendor:
War FTP Daemon
by:
coolkaveh
7,5
CVSS
HIGH
Format String Vulnerability
134
CWE
Product Name: War FTP Daemon
Affected Version From: War FTP Daemon 1.82 RC 11
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: a:warftp:war_ftp_daemon
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2012
War FTP Daemon Remote Format String Vulnerability
War FTP Daemon is vulnerable to a remote format string vulnerability. An attacker can send a maliciously crafted username and password to the FTP server, which can cause the server to crash. This can be exploited by sending a username and password containing format string specifiers to the FTP server.
Mitigation:
Upgrade to the latest version of War FTP Daemon.