PT-2008-6718 · Wing Ftp · Winftp Server

Dmnt

·

Published

2008-12-18

·

Updated

2017-09-29

·

CVE-2008-5666

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions WinFTP FTP Server version 2.3.0
Description The issue allows remote authenticated users to cause a denial of service when passive mode is used. This can be achieved via a sequence of FTP sessions that include an invalid NLST -1 command.
Recommendations For WinFTP FTP Server version 2.3.0, consider disabling the passive mode as a temporary workaround until a patch is available. Restrict access to the FTP server to minimize the risk of exploitation. Avoid using the NLST command with invalid parameters in the affected FTP sessions until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-5666

Affected Products

Winftp Server