VYPR

Password Recover

by SpotFTP

CVEs (2)

  • CVE-2020-37122HigFeb 7, 2026
    risk 0.49cvss 7.5epss 0.00

    SpotFTP-FTP Password Recover 2.4.8 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buffer overflow. Attackers can create a text file with 1000 'Z' characters and input it as a registration code to trigger the…

  • CVE-2019-25711MedApr 12, 2026
    risk 0.40cvss 6.2epss 0.00

    SpotFTP Password Recover 2.4.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized buffer in the Name field during registration. Attackers can generate a 256-byte payload, paste it into the Name input field,…