vendor:
FTP Shell Server
by:
Dino Covotsos
7.5
CVSS
HIGH
Buffer Overflow
Buffer Overflow
CWE
Product Name: FTP Shell Server
Affected Version From: 6.83
Affected Version To: 6.83
Patch Exists: NO
Related CWE: TBC
CPE: a:ftpshell:ftp_shell_server:6.83
Platforms Tested: Windows XP SP3 ENG x86
2019
FTP Shell Server 6.83 ‘Account name to ban’ Buffer Overflow
The FTP Shell Server 6.83 'Account name to ban' feature is vulnerable to a buffer overflow attack. By providing a specially crafted account name, an attacker can trigger the overflow and execute arbitrary code. This exploit was created to demonstrate the vulnerability during intern training in 2019.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of FTP Shell Server or apply any available security patches.