vendor:
Easy FTP Server
by:
Rabih Mohsen
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Easy FTP Server
Affected Version From: 1.7.0.11
Affected Version To: 1.7.0.11
Patch Exists: YES
Related CWE: N/A
CPE: a:easyftpsvr:easy_ftp_server:1.7.0.11
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2010
Easy FTP Server v1.7.0.11 NLST , NLST -al, APPE, RETR , SIZE and XCWD Commands Remote Buffer Overflow Exploit
Easy FTP Server v1.7.0.11 is vulnerable to a remote buffer overflow attack when sending specially crafted commands such as NLST, NLST -al, APPE, RETR, SIZE, and XCWD. An attacker can exploit this vulnerability by sending a malicious payload of 272 bytes to the server, which will overwrite the EIP register and execute arbitrary code. The payload used in this exploit is a 228-byte shellcode generated by Metasploit, which will open a calculator window on the target machine.
Mitigation:
Upgrade to the latest version of Easy FTP Server, or apply the patch provided by the vendor.