vendor:
FlashGet
by:
Krystian Kloskowski
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: FlashGet
Affected Version From: 1.9
Affected Version To: 1.9
Patch Exists: YES
Related CWE: N/A
CPE: a:flashget:flashget:1.9
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2 Polish
2009
FlashGet 1.9 (FTP PWD Response) 0day Remote Buffer Overflow PoC Exploit
FlashGet 1.9 is vulnerable to a remote buffer overflow vulnerability when a maliciously crafted FTP PWD response is sent to the server. This can lead to arbitrary code execution on the vulnerable system. The bug was discovered by Krystian Kloskowski and tested on FlashGet 1.9 running on Windows XP SP2 Polish.
Mitigation:
Upgrade to the latest version of FlashGet 1.9 or later.