S4E just found a medium vulnerable javascript library scanner
medium·Product Based Network Vulnerabilities·Updated Oct 7, 2025

CVE-2005-0850 Scanner

CVE-2005-0850 Scanner - Denial of Service (DoS) vulnerability in FileZilla Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2005-0850
5.0
CVSS

FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS device name such as CON, NUL, COM1, LPT1, and others.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

FileZilla Server is a widely used FTP server application that is popular among web developers, system administrators, and IT professionals. It allows for the easy transfer and management of files over a network, supporting secure transfers and various protocols. Its open-source nature and compatibility with multiple operating systems make it a versatile choice for handling server-side file operations. Despite its benefits, it's crucial to monitor and update the server due to potential vulnerabilities in outdated versions. Regular updates ensure stable performance and security compliance. With a large user base, FileZilla Server is an essential tool in web hosting and data management environments.

Denial of Service (DoS) vulnerabilities in software like FileZilla Server can be critical, as they allow attackers to disrupt services and impact availability. A DoS vulnerability occurs when a system becomes unavailable due to overwhelming malicious requests. In the context of FileZilla Server, attackers can exploit this vulnerability by using special MS-DOS device names in filenames. This kind of attack can result in the server crashing or becoming unresponsive, affecting normal operations. It's essential to patch such vulnerabilities to maintain system integrity and availability.

In technical terms, the vulnerability in FileZilla Server arises from its inability to handle filenames with MS-DOS device names properly. Attackers can exploit this by crafting requests containing reserved names like CON, NUL, COM1, and LPT1. When these names are processed by affected FileZilla Server versions, it leads to unhandled exceptions and service crashes. The endpoint accepting filename inputs is particularly vulnerable. By exploiting this, attackers can cause memory resource exhaustion, bringing the server to a halt. Patching this involves updating to a higher version that circumvents processing such names.

Exploiting this vulnerability can lead to significant disruptions within an organization's IT environment. If malicious actors successfully enact a DoS attack on a FileZilla Server, normal business operations relying on file transfers can be severely hindered. This may result in loss of productivity and potential financial impact due to service downtime. In worst-case scenarios, prolonged unavailability could damage an organization's reputation. Additionally, this vulnerability can be a foothold for more sophisticated attacks if combined with other vulnerabilities.

REFERENCES

Solution Advice
  • Update FileZilla Server to the latest version to ensure the vulnerability is patched.
  • Implement robust input validation to avoid processing of reserved MS-DOS device names.
  • Monitor network traffic for unusual activities that may indicate a DoS attempt.
  • Employ rate limiting to reduce the impact of potential denial of service attempts.
  • Regularly review and adjust security configurations to mitigate new threats.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.