Description
glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large number of * (asterisk) characters.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by ASGUARD LABS · perldosunix
https://www.exploit-db.com/exploits/21074
References (4)
Scores
EPSS
0.0679
EPSS Percentile
91.4%
Details
Status
published
Products (9)
glftpd/glftpd
1.13.6
glftpd/glftpd
1.16.9
glftpd/glftpd
1.17.2
glftpd/glftpd
1.18a
glftpd/glftpd
1.19
glftpd/glftpd
1.20
glftpd/glftpd
1.21
glftpd/glftpd
1.22b
glftpd/glftpd
1.23
Published
Aug 31, 2001
Tracked Since
Feb 18, 2026