vendor:
FileZilla
by:
Kağan Çapar
9.3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: FileZilla
Affected Version From: 3.33
Affected Version To: 3.33
Patch Exists: YES
Related CWE: N/A
CPE: a:filezilla:filezilla:3.33
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux 2018.3 x64
2018
FileZilla 3.33 Buffer-Overflow (PoC)
A buffer overflow vulnerability exists in FileZilla 3.33, which could allow an attacker to execute arbitrary code on the target system. The vulnerability is due to a lack of proper validation of user-supplied input when handling FTP commands. An attacker can exploit this vulnerability by sending a specially crafted FTP command to the target system. Successful exploitation of this vulnerability could result in arbitrary code execution on the target system.
Mitigation:
Upgrade to the latest version of FileZilla, which is 3.45.1.