vendor:
XM Easy Personal FTP Server
by:
leinakesi
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: XM Easy Personal FTP Server
Affected Version From: XM Easy Personal FTP Server 5.8.0
Affected Version To: Earlier versions may also be affected
Patch Exists: NO
Related CWE: N/A
CPE: a:dxmsoft:xm_easy_personal_ftp_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2009
XM Easy Personal FTP Server 5.8.0 Denial of Service Vulnerability
XM Easy Personal FTP Server failed to handle more than 2000 files or folders in the root directory. If an attacker could log on the server, they could upload 2000 files or folders, close the current connection, and then use a FTP client to reconnect the server. This would cause the server to crash, leading to a Denial of Service.
Mitigation:
Ensure that the FTP server is configured to limit the number of files and folders in the root directory.