vendor:
PCMan FTP Server
by:
Luis Noriega
7,5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: PCMan FTP Server
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: YES
Related CWE: N/A
CPE: a:f2bbs:pcman_ftp_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP
2016
PCMan FTP Server 2.0 BoF SITE CHMOD Command
PCMan FTP Server 2.0 is vulnerable to a buffer overflow attack when sending a specially crafted SITE CHMOD command. The vulnerability is caused due to a lack of proper bounds checking of user-supplied data, which can result in a buffer overflow. An attacker can exploit this vulnerability to execute arbitrary code in the context of the application.
Mitigation:
The vendor has released a patch to address this vulnerability.