vendor:
FreeFloat FTP Server
by:
Cybernetic
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: FreeFloat FTP Server
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:freefloat:freefloat_ftp_server:1.00
Platforms Tested: Windows XP Professional SP3 x86
2016
FreeFloat FTP Server HOST Command Buffer Overflow Exploit
This exploit targets a buffer overflow vulnerability in the FreeFloat FTP Server. The vulnerability allows an attacker to execute arbitrary code by sending a specially crafted HOST command to the server. The exploit takes advantage of a return address overwrite in the HOST command buffer to redirect program execution flow to a shellcode payload. The shellcode payload used in this exploit is a reverse TCP shell from the Metasploit Framework. The exploit has been tested on Windows XP Professional SP3 x86.
Mitigation:
Apply the latest patch or upgrade to a non-vulnerable version of FreeFloat FTP Server.