Vulnerabilities
Vulnerable Software
Crob:  Security Vulnerabilities
Crob FTP Server 3.6.1 b.263 allows remote attackers to cause a denial of service via a long series of "?A" sequences in the (1) LIST and possibly (2) NLST command.
CVSS Score
5.0
EPSS Score
0.066
Published
2006-12-14
Multiple buffer overflows in Crob FTP 3.6.1, and possibly earlier versions, allow remote attackers to execute arbitrary code via (1) an FTP command with a large string followed by the RMD command with a long string or (2) a globbing ("*") character followed by a long string.
CVSS Score
7.5
EPSS Score
0.054
Published
2005-06-09
Directory traversal vulnerability in Crob FTP Server 3.5.1 allows local users to browse outside the FTP root via multiple ../ (dot dot slash) in the DIR command.
CVSS Score
2.1
EPSS Score
0.002
Published
2004-12-31
Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disconnecting from the server.
CVSS Score
5.0
EPSS Score
0.043
Published
2004-11-23
Crob FTP Server 3.5.1 allows remote authenticated users to cause a denial of service (crash) via a dir command with a large number of "." characters followed by a "/*" string.
CVSS Score
5.0
EPSS Score
0.044
Published
2004-02-01
Crob FTP Server 2.60.1 allows remote authenticated users to cause a denial of service (crash) by renaming a file to the "con" MS-DOS device name.
CVSS Score
5.0
EPSS Score
0.009
Published
2003-08-06
Format string vulnerability in Crob FTP Server 2.60.1 allows remote attackers to cause a denial of service (crash) via "%s" or "%n" sequences in (1) the username during login, or other FTP commands such as (2) dir.
CVSS Score
5.0
EPSS Score
0.011
Published
2003-06-03


Contact Us

Shodan ® - All rights reserved