Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2005-0850

Severity
5.0MEDIUM
EPSS
0.1%
top 66.04%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 2
Latest updateMay 1

Description

FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS device name such as CON, NUL, COM1, LPT1, and others.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j5g3-gp7m-r7r9: FileZilla FTP server before 02022-05-01
CVEList
CVE-2005-0850: FileZilla FTP server before 02005-03-24

💥Exploits & PoCs

1
Nuclei
FileZilla Server < 0.9.6 - DoS via MS-DOS Device Names

💬Community

1
Bugzilla
CVE-2005-0850 filezilla: DoS via MS-DOS device name2020-07-30
CVE-2005-0850 (MEDIUM CVSS 5) | FileZilla FTP server before 0.9.6 a | cvebase.io