vendor:
FreeFloat FTP Server
by:
mortis
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: FreeFloat FTP Server
Affected Version From: 1
Affected Version To: 1
Patch Exists: YES
Related CWE:
CPE: a:freefloat:freefloat_ftp_server:1.00
Platforms Tested: Windows XP SP3 English
2011
FreeFloat FTP Server ACCL Buffer Overflow Exploit
This exploit allows an attacker to execute arbitrary code by sending a specially crafted ACCL command to the FreeFloat FTP Server. The vulnerability occurs due to a buffer overflow in the server's handling of ACCL commands. By sending a long string of characters as the argument to the ACCL command, an attacker can overwrite the stack and gain control of the server's execution flow. This exploit opens a listener shell on port 4444.
Mitigation:
The vendor has released a patch for this vulnerability. Users are advised to update to the latest version of FreeFloat FTP Server to mitigate the risk of exploitation.