vendor:
FTPGetter Professional
by:
FULLSHADE
7.5
CVSS
HIGH
NULL pointer dereference
476
CWE
Product Name: FTPGetter Professional
Affected Version From: 5.97.0.223
Affected Version To: 5.97.0.223
Patch Exists: YES
Related CWE: CVE-2020-5183
CPE: a:ftpgetter:ftpgetter_professional:5.97.0.223
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7
2020
FTPGetter Professional 5.97.0.223 – Denial of Service (PoC)
The FTPGetter Professional v.5.97.0.223 FTP client suffers from a NULL pointer dereference vulnerability via the program not properly handling user input when setting the field 'Run program' under profile properties, it triggers when executing the profile.
Mitigation:
Vendor contacted and patched the vulnerability.