Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2005-0851

CWE-8355 documents5 sources
Severity
5.0MEDIUM
EPSS
0.0%
top 87.80%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 2
Latest updateMay 1

Description

FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of service (infinite loop) via certain file uploads or directory listings.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-p4rv-2523-rg59: FileZilla FTP server before 02022-05-01
CVEList
CVE-2005-0851: FileZilla FTP server before 02005-03-24

💥Exploits & PoCs

1
Nuclei
FileZilla Server < 0.9.6 - DoS via MODE Z Infinite Loop

💬Community

1
Bugzilla
CVE-2005-0851 filezilla: DoS via certain file uploads2020-07-30
CVE-2005-0851 (MEDIUM CVSS 5) | FileZilla FTP server before 0.9.6 | cvebase.io