// For flags

CVE-2004-0255

Xlight FTP Server 1.x - Long Directory Request Remote Denial of Service

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long directory consisting of . (dot) and / (slash) characters, which causes the server to crash when the administrator views the log file, possibly triggering a buffer overflow.

Xlight 1.52, con registro de mensajes en pantalla activado, permite a atacantes remotos causar una denegación de servicio solicitando un directorio largo consistente en caractéres . (punto) y / (barra), lo que hace que el servidor se caiga cuando el administrador visualiza el fichero de registro, posiblemente disparando un desbordamiento de búfer.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2004-02-05 First Exploit
  • 2004-03-17 CVE Reserved
  • 2004-03-18 CVE Published
  • 2024-08-08 CVE Updated
  • 2025-01-14 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Xlight Ftp Server
Search vendor "Xlight Ftp Server"
Xlight Ftp Server
Search vendor "Xlight Ftp Server" for product "Xlight Ftp Server"
1.25
Search vendor "Xlight Ftp Server" for product "Xlight Ftp Server" and version "1.25"
-
Affected
Xlight Ftp Server
Search vendor "Xlight Ftp Server"
Xlight Ftp Server
Search vendor "Xlight Ftp Server" for product "Xlight Ftp Server"
1.41
Search vendor "Xlight Ftp Server" for product "Xlight Ftp Server" and version "1.41"
-
Affected
Xlight Ftp Server
Search vendor "Xlight Ftp Server"
Xlight Ftp Server
Search vendor "Xlight Ftp Server" for product "Xlight Ftp Server"
1.45
Search vendor "Xlight Ftp Server" for product "Xlight Ftp Server" and version "1.45"
-
Affected
Xlight Ftp Server
Search vendor "Xlight Ftp Server"
Xlight Ftp Server
Search vendor "Xlight Ftp Server" for product "Xlight Ftp Server"
1.52
Search vendor "Xlight Ftp Server" for product "Xlight Ftp Server" and version "1.52"
-
Affected