vendor:
UplusFtp Server
by:
b0telh0
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: UplusFtp Server
Affected Version From: 1.7.0.12
Affected Version To: 1.7.0.12
Patch Exists: YES
Related CWE: N/A
CPE: a:uplusftp:uplusftp_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2010
UplusFtp Server 1.7.0.12 Remote Buffer Overflow
UplusFtp Server 1.7.0.12 is vulnerable to a remote buffer overflow attack. The vulnerability exists in the CWD, DELE, LIST, MKD, NLST (and etc) commands. An attacker can exploit this vulnerability by sending a specially crafted payload to the vulnerable server. This payload contains a malicious shellcode that will be executed on the vulnerable system.
Mitigation:
Upgrade to the latest version of UplusFtp Server.