vendor:
freeFTPd
by:
Wireghoul
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: freeFTPd
Affected Version From: 1.0.10
Affected Version To: 1.0.10
Patch Exists: NO
Related CWE:
CPE: a:freeftpd:freeftpd:1.0.10
Platforms Tested: Windows XP SP3
2013
freeFTPd 1.0.10 anonymous-auth PASS SEH buffer overflow
The exploit takes advantage of a buffer overflow vulnerability in freeFTPd 1.0.10. It allows an attacker to execute arbitrary code by sending a specially crafted payload to the server. The exploit uses an egghunter technique to find and execute the shellcode. The shellcode spawns a cmd.exe shell. The exploit has been tested on Windows XP SP3.
Mitigation:
Upgrade to a patched version of freeFTPd.