vendor:
FreeFloat FTP Server
by:
D35m0nd142
7.5
CVSS
HIGH
Remote Command Execution
119
CWE
Product Name: FreeFloat FTP Server
Affected Version From: Not provided
Affected Version To: Not provided
Patch Exists: NO
Related CWE: Not provided
CPE: Not provided
Platforms Tested: Windows XP SP3, Ubuntu 12.04
2012
FreeFloat FTP Server Remote Command Execution USER Command Buffer Overflow
This exploit takes advantage of a buffer overflow vulnerability in the USER command of FreeFloat FTP Server. By sending a specially crafted payload, an attacker can execute arbitrary commands on the target system. The exploit uses a combination of junk data, a return address, and a payload to achieve code execution.
Mitigation:
The vendor has not provided a patch or mitigation for this vulnerability. It is recommended to discontinue the use of FreeFloat FTP Server and switch to a more secure alternative.