PT-2006-3152 · Filezilla · Filezilla Ftp Server

Leon Juranic

·

Published

2006-05-04

·

Updated

2017-07-20

·

CVE-2006-2173

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions FileZilla FTP Server version 2.2.22
Description The issue allows remote authenticated attackers to cause a denial of service and possibly execute arbitrary code. This can be achieved via a long PORT or PASS command followed by the MLSD command, or through the remote server interface.
Recommendations For FileZilla FTP Server version 2.2.22, consider updating to a newer version that addresses this issue. As a temporary workaround, restrict access to the MLSD command and limit the length of PORT and PASS commands to prevent exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2173

Affected Products

Filezilla Ftp Server