vendor:
WS_FTP LE
by:
Zahid Adeel
9,3
CVSS
HIGH
SEH Overwrite
119
CWE
Product Name: WS_FTP LE
Affected Version From: 12.3
Affected Version To: 12.3
Patch Exists: YES
Related CWE: N/A
CPE: a:ipswitch:ws_ftp_le:12.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 8.1 x64 Pro
2016
Ipswitch WS_FTP LE 12.3 – Search field SEH Overwrite POC
A buffer overflow vulnerability exists in Ipswitch WS_FTP LE 12.3 when a specially crafted file is used in the Local Search option of the Tools menu. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application.
Mitigation:
Upgrade to the latest version of Ipswitch WS_FTP LE 12.3 or apply the patch provided by the vendor.