CVE-2008-4500
Serv-U 7.0.0.1-7.3 - Authenticated Denial of Service via STOU Command
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4500. PoCs published by dmnt.
AI-analyzed exploit summary This exploit demonstrates a Denial of Service (DoS) vulnerability in Serv-U FTP Server versions <= 7.2.0.1 and 7.3 by sending a specially crafted STOU command. The server crashes upon receiving the command, requiring manual restart.
Description
Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted stou command, probably related to MS-DOS device names, as demonstrated using "con:1".
Exploits (1)
This exploit demonstrates a Denial of Service (DoS) vulnerability in Serv-U FTP Server versions <= 7.2.0.1 and 7.3 by sending a specially crafted STOU command. The server crashes upon receiving the command, requiring manual restart.