vendor:
Easy FTP Server
by:
Karn Ganeshen
9.8
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: Easy FTP Server
Affected Version From: 1.7.0.11
Affected Version To: 1.7.0.11
Patch Exists: NO
Related CWE:
CPE: a:easy_ftp_server:easy_ftp_server:1.7.0.11
Platforms Tested: Windows XP Pro SP2 [Eng] and Windows XP Pro SP3 [Eng]
2010
Easy FTP Server v1.7.0.11 [LIST] Remote BoF Exploit Post Authentication
This exploit allows remote attackers to execute arbitrary code on the target system by sending a specially crafted LIST command to the Easy FTP Server v1.7.0.11 after authentication.
Mitigation:
Update to a patched version of Easy FTP Server or use an alternative FTP server software.