vendor:
Encrypted FTP (EFTP)
by:
ByteRage
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Encrypted FTP (EFTP)
Affected Version From: 2.0.7.337
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:encrypted_ftp_project:encrypted_ftp:2.0.7.337
Platforms Tested: Windows
Unknown
Encrypted FTP (EFTP) Remote Code Execution
A malicious user with upload permissions to the target host can cause a buffer overflow in EFTP to execute code of the attacker's choosing. The attacker can potentially use this exploit to open a bindshell on the target host. Another possible result of this exploit is a denial of service.
Mitigation:
Update EFTP to a patched version or consider using an alternative FTP application.