vendor:
FTPGetter
by:
Paul Purcell
7.5
CVSS
HIGH
Remote Code Execution
CWE
Product Name: FTPGetter
Affected Version From: FTPGetter 5.89.0.85
Affected Version To: Earlier versions
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Pro 1703 x64
2017
FTPGetter 5.89.0.85 Remote SEH Buffer Overflow
There is a buffer overflow in the log viewer/parser of FTPGetter. When a malicious ftp server returns a long 331 response, the overflow overwrites SEH produced is exploitable. There are many bad characters, so I had to ascii encode everything. My PoC runs code to launch a command shell. Also note the time of day is displayed in the log viewer, which will change the length of the buffer needed. Just adjust your sled accordingly.