S4E just found a medium vulnerable javascript library scanner
medium·Product Based Network Vulnerabilities·Updated Oct 7, 2025

CVE-2006-2173 Scanner

CVE-2006-2173 Scanner - Buffer Overflow vulnerability in FileZilla FTP Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2006-2173
6.4
CVSS

Buffer overflow in FileZilla FTP Server 2.2.22 allows remote authenticated attackers to cause a denial of service and possibly execute arbitrary code via a long (1) PORT or (2) PASS followed by the MLSD command, or (2) the remote server interface, as demonstrated by the Infigo FTPStress Fuzzer.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

FileZilla FTP Server is a widely used open-source FTP server application designed to facilitate the transfer of files between computers over a network. It is primarily utilized by system administrators and professional users who require a reliable and efficient tool for managing file uploads and downloads. The software is popular for its user-friendly interface and support for various FTP protocols, including FTP, FTPS, and SFTP. Beyond enterprise settings, FileZilla is often deployed in educational institutions, small businesses, and personal networks to maintain and organize digital content. Its cross-platform compatibility allows it to be used on different operating systems, enhancing accessibility and convenience for diverse user groups. However, like many software solutions, FileZilla is susceptible to vulnerabilities, one of which is explored by examining version 2.2.22.

The buffer overflow vulnerability in FileZilla FTP Server version 2.2.22 poses significant security risks by allowing unauthorized remote authenticated attackers to execute arbitrary code or cause a denial of service. Triggered by excessively long input via PORT or PASS commands, this flaw could result in memory corruption, leading to system instability or lateral movement within a network. The vulnerability arises from inadequate input validation mechanisms, common in numerous legacy systems, posing heightened risks for organizations using outdated software. Attackers leveraging this vulnerability may gain unauthorized access, compromising data integrity, confidentiality, and availability. Proper awareness and timely remediation can mitigate potential damages caused by exploiting this flaw in susceptible systems.

The buffer overflow exploit detailed in CVE-2006-2173 highlights the vulnerability's technical aspects within FileZilla FTP Server's version 2.2.22. Specifically, the exploit occurs when an attacker transmits overly lengthy PORT or PASS commands, exceeding the buffer's capacity. This action causes the server to overwrite adjacent memory segments, potentially disrupting normal function or opening avenues for malicious code execution via MLSD commands. Vulnerable input endpoints are primarily found in the FTP server's command processing routines, illustrating a common attack vector in legacy systems where input validation inadequacies existed. This vulnerability relies on authenticated access to execute, emphasizing the need for robust authentication and input validation practices across similar systems to prevent exploitation effectively.

Once exploited, the buffer overflow vulnerability in FileZilla FTP Server can have severe implications, such as enabling attackers to execute arbitrary code with the same privileges as the affected service. This may lead to unauthorized data access, system tampering, and data manipulation, undermining the server's integrity and reliability. Additionally, a successful exploit can trigger a denial-of-service condition, temporarily disrupting legitimate access and affecting business continuity. Organizations with vulnerable FileZilla FTP Server deployments may face reputational damage, compliance penalties, and financial losses due to potential data breaches or service disruptions, emphasizing the need for timely detection and remediation of such vulnerabilities.

REFERENCES

Solution Advice
  • Upgrade to a version of FileZilla FTP Server that is not affected by CVE-2006-2173.
  • Apply vendor-recommended patches immediately upon their release.
  • Implement strict input validation protocols to prevent buffer overflow attacks.
  • Restrict FTP server access to trusted users and minimize privilege levels where possible.
  • Conduct regular security audits and vulnerability assessments to identify potential weaknesses.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2006-2173 Scanner - Buffer Overflow vulnerability in FileZilla FTP Server S4E