CVE-2008-5666

WinFTP FTP Server 2.3.0 - DoS

Title source: llm

Description

WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of service via a sequence of FTP sessions that include an invalid "NLST -1" command.

Exploits (3)

exploitdb WORKING POC VERIFIED
by dmnt · pythondoswindows
https://www.exploit-db.com/exploits/6717
exploitdb WORKING POC VERIFIED
by Julien Bedard · perldoswindows
https://www.exploit-db.com/exploits/6581
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/windows/ftp/winftp230_nlst.rb

Scores

EPSS 0.6329
EPSS Percentile 98.4%

Details

CWE
CWE-399
Status published
Products (1)
wftpserver/winftp_ftp_server 2.3.0
Published Dec 19, 2008
Tracked Since Feb 18, 2026