CVE-2001-0697
NetWin SurgeFTP < 1.1h - Denial of Service via 'ls ..' Command
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2001-0697. PoCs published by the Strumpf Noir Society.
AI-analyzed exploit summary This exploit demonstrates a denial of service (DoS) vulnerability in SurgeFTP by sending a malformed directory listing request. The server crashes when a client requests a listing of the directory above the root directory after logging in.
Description
NetWin SurgeFTP prior to 1.1h allows a remote attacker to cause a denial of service (crash) via an 'ls ..' command.
Exploits (1)
This exploit demonstrates a denial of service (DoS) vulnerability in SurgeFTP by sending a malformed directory listing request. The server crashes when a client requests a listing of the directory above the root directory after logging in.