vendor:
CuteFTP
by:
Dr_IDE
7.8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: CuteFTP
Affected Version From: 8.3.2003
Affected Version To: 8.3.2003
Patch Exists: YES
Related CWE: N/A
CPE: a:globalscape:cuteftp:8.3.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 RC, XP
2009
CuteFTP v8.3.3 Home/Pro/Lite Create New Site Local Buffer Overflow PoC
This PoC exploits the 'Create New Site' mechanism. Any site type that you pick will work. Because of differences in the internal process of each site type you may be able to get execution through one of these channels.
Mitigation:
Ensure that all user input is validated and sanitized before being used in any application.