Description
SpotFTP-FTP Password Recover 2.4.8 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buffer overflow. Attackers can create a text file with 1000 'Z' characters and input it as a registration code to trigger the application crash.
Problem types
Product status
Credits
Ismael Nava
References
www.exploit-db.com/exploits/48132 (ExploitDB-48132)
www.nsauditor.com/ (Vendor Homepage)
www.nsauditor.com/spotftp.html (Software Download Page)
www.vulncheck.com/...-ftp-password-recover-denial-of-service (VulnCheck Advisory: SpotFTP-FTP Password Recover 2.4.8 - Denial of Service)