vendor:
Easy FTP Server
by:
Glafkos Charalambous
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Easy FTP Server
Affected Version From: 1.7.0.11
Affected Version To: 1.7.0.11
Patch Exists: YES
Related CWE: N/A
CPE: a:easyftpsvr:easy_ftp_server:1.7.0.11
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 En
2010
Easy FTP Server v1.7.0.11 Multiple Command Buffer Overflow
A buffer overflow vulnerability exists in Easy FTP Server v1.7.0.11 when handling specially crafted commands such as DELE, STOR, RNFR, RMD, and XRMD. An attacker can exploit this vulnerability by sending a specially crafted command with a payload of 268 bytes or more. This will overwrite the EIP register and allow the attacker to execute arbitrary code.
Mitigation:
Upgrade to the latest version of Easy FTP Server.