vendor:
DreamFTPServer
by:
Greg Priest
9,3
CVSS
HIGH
Format String Vulnerability
134
CWE
Product Name: DreamFTPServer
Affected Version From: DreamFTPServer1.0.2
Affected Version To: DreamFTPServer1.0.2
Patch Exists: YES
Related CWE: N/A
CPE: a:dreamftpserver:dreamftpserver:1.0.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows7 x64 HUN/ENG Professional
2016
DreamFTPServer1.0.2_RETR_command_format_string_remotecodevuln
DreamFTPServer1.0.2 is vulnerable to a format string vulnerability in the RETR command. An attacker can send a maliciously crafted string to the server, which can lead to remote code execution. The exploit code sends a string containing format specifiers and shellcode to the server, which is then executed.
Mitigation:
Upgrade to the latest version of DreamFTPServer