vendor:
CrushFTP 5
by:
BSOD Digital (Fabien DROMAS)
9.3
CVSS
HIGH
Remote Code Execution
119
CWE
Product Name: CrushFTP 5
Affected Version From: 5.7.0_96
Affected Version To: 5.7.0_96
Patch Exists: YES
Related CWE: N/A
CPE: a:crushftp:crushftp_5
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2011
Crush FTP 5 ‘APPE’ command Remote BSOD Poc Exploit
This exploit is a proof of concept for a remote code execution vulnerability in Crush FTP 5. The vulnerability is triggered by sending a specially crafted 'APPE' command with 9000 bytes of data. This causes a buffer overflow which leads to a Blue Screen of Death (BSOD) on the target system.
Mitigation:
Upgrade to the latest version of Crush FTP 5, which is not vulnerable to this exploit.