vendor:
FTP Commander Pro
by:
boku
7.5
CVSS
HIGH
Local Stack Overflow
119
CWE
Product Name: FTP Commander Pro
Affected Version From: 08.02
Affected Version To: 08.03
Patch Exists: NO
Related CWE:
CPE: a:internet-soft:ftp_commander_pro:8.03
Platforms Tested: Windows Vista, Windows XP, Windows 10
2019
FTP Commander Pro 8.03 – Local Stack Overflow
This exploit allows an attacker to trigger a stack overflow vulnerability in FTP Commander Pro version 8.03 and execute arbitrary code on the target system. The vulnerability occurs when a specially crafted payload is sent to the FTP server, causing the program to crash and open the calculator application.
Mitigation:
Update to a patched version of FTP Commander Pro.