vendor:
FreeFloat FTP Server
by:
Eagleblack
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: FreeFloat FTP Server
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:freefloat:freefloat_ftp_server:1.00
Platforms Tested: Windows XP Professional SP3 Spanish version x86
2016
FreeFloat FTP Server RENAME Command Buffer Overflow Exploit
FreeFloat FTP server allows login as root without a user and password, this vulnerability allows an attacker to login and send a long chain of characters that overflow the buffer. When the attacker knows the exact number that overwrites the EIP registry, they can take possession of the application and send a malicious code (payload) to the ESP stack pointer that allows obtaining remote code execution on the system running the FTP Server, in this case Windows XP.
Mitigation:
Update to the latest version of FreeFloat FTP Server or apply patches provided by the vendor.