Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2006-6565

Severity
4.0MEDIUM
EPSS
71.5%
top 1.27%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedDec 15
Latest updateMay 1

Description

FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) NLST commands, which results in a NULL pointer dereference, a different set of vectors than CVE-2006-6564. NOTE: CVE analysis suggests that the problem might be due to a malformed PORT command.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 8.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-42fr-8xjf-ghxh: FileZilla Server before 02022-05-01
CVEList
CVE-2006-6565: FileZilla Server before 02006-12-15

💥Exploits & PoCs

2
Exploit-DB
FileZilla FTP Server 0.9.21 - 'LIST/NLST' Denial of Service2006-12-11
Nuclei
FileZilla Server < 0.9.22 - DoS via Wildcard Commands

💬Community

1
Bugzilla
CVE-2006-6565 filezilla: allows remote attackers to cause a denial of service via wildcard argument2020-07-30
CVE-2006-6565 (MEDIUM CVSS 4) | FileZilla Server before 0.9.22 allo | cvebase.io