vendor:
CesarFTP
by:
MC
N/A
CVSS
N/A
Buffer Overflow
119
CWE
Product Name: CesarFTP
Affected Version From: 0.99g
Affected Version To: 0.99g
Patch Exists: YES
Related CWE: CVE-2006-2961
CPE: a:cesarftp:cesarftp:0.99g
Metasploit:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 2000 Pro SP4 English, Windows 2000 Pro SP4 French, Windows XP SP2/SP3 English, Windows 2003 SP1 English
2006
Cesar FTP 0.99g MKD Command Buffer Overflow
This module exploits a stack buffer overflow in the MKD verb in CesarFTP 0.99g. You must have valid credentials to trigger this vulnerability. Also, you only get one chance, so choose your target carefully.
Mitigation:
Upgrade to the latest version of CesarFTP 0.99g