CVE-2008-1052

NetWin SurgeFTP <= 2.3a2 - Denial of Service via Large Content-Length Header

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-1052. PoCs published by Luigi Auriemma.

AI-analyzed exploit summary This exploit triggers a denial-of-service in SurgeFTP by sending an HTTP request with an excessively large Content-Length value, causing the server to crash due to inadequate boundary checks.

Description

The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL pointer dereference when memory allocation fails.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Luigi Auriemma · textdoswindows
https://www.exploit-db.com/exploits/31302

This exploit triggers a denial-of-service in SurgeFTP by sending an HTTP request with an excessively large Content-Length value, causing the server to crash due to inadequate boundary checks.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: SurgeFTP 2.3a2
No auth needed
Prerequisites: Network access to the SurgeFTP server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/488745/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29096
Third Party Advisory x_refsource_misc
http://aluigi.altervista.org/adv/surgeftpizza-adv.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/40843
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3704
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27993

Scores

EPSS 0.0691
EPSS Percentile 91.5%

Details

CWE
CWE-119
Status published
Products (1)
netwin/surgeftp 2.3a2
Published Feb 27, 2008
Tracked Since Feb 18, 2026