CVE-2006-6565
NUCLEIFileZilla Server <0.9.22 - DoS
Title source: llmDescription
FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) NLST commands, which results in a NULL pointer dereference, a different set of vectors than CVE-2006-6564. NOTE: CVE analysis suggests that the problem might be due to a malformed PORT command.
Exploits (2)
metasploit
WORKING POC
by aushack · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/windows/ftp/filezilla_server_port.rb
Nuclei Templates (1)
FileZilla Server < 0.9.22 - DoS via Wildcard Commands
MEDIUMVERIFIEDby pussycat0x
Shodan:
product:"FileZilla"
References (4)
Scores
EPSS
0.7154
EPSS Percentile
98.7%
Classification
CWE
CWE-476
Status
draft
Affected Products (1)
filezilla-project/filezilla_server
< 0.9.22
Timeline
Published
Dec 15, 2006
Tracked Since
Feb 18, 2026