S4E just found a medium vulnerable javascript library scanner
medium·Product Based Network Vulnerabilities·Updated Oct 7, 2025

CVE-2006-6565 Scanner

CVE-2006-6565 Scanner - Denial of Service (DoS) vulnerability in FileZilla Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2006-6565
4.0
CVSS

FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) NLST commands, which results in a NULL pointer dereference, a different set of vectors than CVE-2006-6564. NOTE: CVE analysis suggests that the problem might be due to a malformed PORT command.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

FileZilla Server is widely used as an FTP server solution across various industries, from small businesses to large enterprises. It allows organizations to facilitate secure and efficient file transfers within and outside the company. System administrators leverage FileZilla Server to establish file transfer protocols within a secure network, ensuring the safe exchange of sensitive data. Many hosting providers also employ FileZilla Server to offer FTP services to their clients. Version management and security are crucial due to the potential vulnerabilities old versions may present. Updating to the latest secure version is a standard practice to maintain data integrity and protect against common threats.

The Denial of Service (DoS) vulnerability affects older versions of FileZilla Server, specifically those before 0.9.22. It is triggered by processing wildcard arguments in specific FTP commands which may lead to a server crash. This vulnerability is a result of improper handling of malformed commands, causing a NULL pointer dereference. When exploited successfully, it can cause the server to become unresponsive. Mitigation involves closely monitoring FTP command usage to prevent unauthorized command execution. Keeping software updated helps to protect against known vulnerabilities like this one.

This vulnerability specifically pertains to FTP commands LIST/NLST when used with wildcard arguments. Malformed PORT commands can also trigger the vulnerability. Exploiting this vulnerability does not require elevated privileges, which makes it more accessible to potential attackers. The vulnerable endpoint is the FTP command processing functionality of FileZilla Server. Effective capture and filtering of malformed commands are crucial to avoiding potential server crashes. Regular security testing and monitoring can help in early detection of such exploits in the network.

The potential effects of exploiting this vulnerability include a complete stop of the FTP service, leading to a denial of service for legitimate users. Extended downtime may result in loss of productivity and potential data loss. Organizations may face reputational damage due to an interruption in services. Malicious actors could use this vulnerability as a distraction while conducting parallel attacks. Financial losses could occur due to prolonged service outages and remediation efforts. Continued exploitation could lead to severe disruption of critical business operations that depend on reliable FTP services.

REFERENCES

Solution Advice
  • Upgrade FileZilla Server to the latest version above 0.9.22 to mitigate this vulnerability.
  • Implement network monitoring to detect an unusual spike in FTP command usage.
  • Limit wildcard command usage and validate incoming FTP commands meticulously to prevent malformed requests.
  • Conduct regular security assessments to identify potential vulnerabilities.
  • Maintain a robust incident response plan to quickly address any service disruptions.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.