vendor:
Sami FTP Server
by:
n30m1nd
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Sami FTP Server
Affected Version From: 2.0.2
Affected Version To: 2.0.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7 64-bit, Windows 10 64-bit
2016
Sami FTP Server 2.0.2- SEH Overwrite, Buffer Overflow by n30m1nd
This exploit targets Sami FTP Server version 2.0.2 and leverages a SEH (Structured Exception Handling) overwrite vulnerability to execute arbitrary code. By sending a specially crafted request to the FTP server, an attacker can overwrite the SEH record and gain control of the program's execution flow, allowing them to execute their own shellcode. The exploit code provided in the script demonstrates how to achieve this.
Mitigation:
To mitigate this vulnerability, users should update to a patched version of the Sami FTP Server software. Additionally, it is recommended to implement network-level protections such as firewalls and intrusion detection systems to detect and block any malicious requests.