vendor:
FileCOPA FTP Server
by:
Umesh Wanve
7.5
CVSS
HIGH
Remote Buffer Overflow
119
CWE
Product Name: FileCOPA FTP Server
Affected Version From: <= 1.01
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:filecopa_ftp_server:filecopa_ftp_server:1.01
Platforms Tested: Windows 2000 SP4 Server English, Windows 2000 SP4 Professional English
2007
FileCOPA FTP Server <= 1.01 (LIST) Remote Buffer Overflow Exploit(2)
We can write some assembly instruction to jump into shellcode. At the time of EIP overwrite, ECX points to our hole request(LIST evil). So jumping forward into ECX points to our Shellcode.
Mitigation:
Apply the latest patch or upgrade to a newer version of the software.