PT-2006-3152 · Filezilla · Filezilla Ftp Server

Leon Juranic

·

Publicado

2006-05-04

·

Atualizado

2017-07-20

·

CVE-2006-2173

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions FileZilla FTP Server version 2.2.22
Description The issue allows remote authenticated attackers to cause a denial of service and possibly execute arbitrary code. This can be achieved via a long PORT or PASS command followed by the MLSD command, or through the remote server interface.
Recommendations For FileZilla FTP Server version 2.2.22, consider updating to a newer version that addresses this issue. As a temporary workaround, restrict access to the MLSD command and limit the length of PORT and PASS commands to prevent exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2173

Produtos afetados

Filezilla Ftp Server