vendor:
FTPShell Client
by:
Peter Baris
9,8
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: FTPShell Client
Affected Version From: 6.53
Affected Version To: 6.53
Patch Exists: YES
Related CWE: CVE-2017-6465
CPE: a:saptech-erp:ftpshell_client
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Server 2008 R2 Standard x64
2017
FTPShell Client 6.53 buffer overflow on making initial connection
A buffer overflow vulnerability exists in FTPShell Client 6.53 when making an initial connection. An attacker can send a specially crafted request containing an overly long string to the FTP server, which can cause a stack-based buffer overflow and allow the attacker to execute arbitrary code on the vulnerable system.
Mitigation:
Upgrade to the latest version of FTPShell Client 6.53 or later.