CVE-2006-5728
XM Easy Personal FTP Server <= 5.2.1 - Authenticated Denial of Service via NLST Command
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5728. PoCs published by boecke.
AI-analyzed exploit summary This Perl script exploits a denial-of-service vulnerability in XM Easy Personal FTP Server <= 5.2.1 by sending an oversized 'NLST -al' command after authentication. The exploit triggers a crash by sending 9000 bytes of data, causing the FTP server to become unresponsive.
Description
XM Easy Personal FTP Server 5.2.1 and earlier allows remote authenticated users to cause a denial of service via a long argument to the NLST command, possibly involving the -al flags.
Exploits (1)
This Perl script exploits a denial-of-service vulnerability in XM Easy Personal FTP Server <= 5.2.1 by sending an oversized 'NLST -al' command after authentication. The exploit triggers a crash by sending 9000 bytes of data, causing the FTP server to become unresponsive.