CVE-2006-6565

NUCLEI

FileZilla Server <0.9.22 - DoS

Title source: llm

Description

FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) NLST commands, which results in a NULL pointer dereference, a different set of vectors than CVE-2006-6564. NOTE: CVE analysis suggests that the problem might be due to a malformed PORT command.

Exploits (2)

metasploit WORKING POC
by aushack · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/windows/ftp/filezilla_server_port.rb
exploitdb WORKING POC VERIFIED
by shinnai · phpdoswindows
https://www.exploit-db.com/exploits/2914

Nuclei Templates (1)

FileZilla Server < 0.9.22 - DoS via Wildcard Commands
MEDIUMVERIFIEDby pussycat0x
Shodan: product:"FileZilla"

Scores

EPSS 0.7154
EPSS Percentile 98.7%

Classification

CWE
CWE-476
Status draft

Affected Products (1)

filezilla-project/filezilla_server < 0.9.22

Timeline

Published Dec 15, 2006
Tracked Since Feb 18, 2026