PT-2004-2978 · Sami · Sami Ftp Server
Published
2004-02-13
·
Updated
2017-07-11
·
CVE-2004-2082
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Sami FTP Server version 1.1.3
Description
The issue allows remote authenticated users to cause a denial of service, resulting in a crash of the pmsystem.exe process. This can be achieved by sending a GET request with a large number of leading "/" (slash) characters.
Recommendations
For Sami FTP Server version 1.1.3, consider restricting access to the server to prevent remote authenticated users from sending malicious GET requests until a fix is available. As a temporary workaround, limit the number of leading "/" characters that can be processed by the server to prevent the denial of service.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sami Ftp Server