vendor:
CoreFTP
by:
Hodorsec
7.5
CVSS
HIGH
Denial of Service
CWE
Product Name: CoreFTP
Affected Version From: Version 2.0, build 653, 32-bit
Affected Version To: Version 2.0, build 653, 32-bit
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 8.1 6.3 (build 9600)
2019
Core FTP 2.0 build 653 – ‘PBSZ’ – Unauthenticated – Denial of Service (PoC)
CoreFTP 2.0 is vulnerable to a Denial of Service attack via the PBSZ command. The PBSZ command in CoreFTP allows for a certain length of the string to be vulnerable to a DoS. This script triggers the DoS by filling ECX with the intended buffer. Although NSEH/SEH is overwritten, the executable binary is SafeSEH protected and no other assemblies are referenced.