vendor:
Easy~Ftp Server
by:
loneferret
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Easy~Ftp Server
Affected Version From: 1.7.0.2
Affected Version To: 1.7.0.2
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP2/SP3 Professional
2010
Easy~Ftp Server v1.7.0.2 Post-Authentication BoF (SEH) (PoC)
This exploit takes advantage of a buffer overflow vulnerability in Easy~Ftp Server v1.7.0.2. It specifically targets the MKD and DELE commands, using a payload that contains bad characters. By sending a specially crafted request, an attacker can cause a stack-based buffer overflow, potentially leading to remote code execution.
Mitigation:
The vendor has not released a patch for this vulnerability. To mitigate the risk, it is recommended to restrict access to the affected application or use alternative software.