vendor:
ComSndFTP FTP Server
by:
demonalex/ChaoYi.Huang
5
CVSS
MEDIUM
Format String Overflow
134
CWE
Product Name: ComSndFTP FTP Server
Affected Version From: ComSndFTP 1.3.7 Beta
Affected Version To: ComSndFTP 1.3.7 Beta
Patch Exists: NO
Related CWE: N/A
CPE: a:comsnd:comsndftp_ftp_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2012
ComSndFTP Server Remote Format String Overflow Vulnerability
ComSndFTP Server is a free ftp server for windows. It is possible for remote attackers to use USER command with any format string that will lead to a Denial Of Service flaw for the FTP service.
Mitigation:
Ensure that user input is properly validated and sanitized before being used in any system operations.