header-logo
Suggest Exploit
vendor:
FTPPad
by:
corelanc0d3r
7.5
CVSS
HIGH
Stack Buffer Overflow
121
CWE
Product Name: FTPPad
Affected Version From: 1.2.2000
Affected Version To: 1.2.2000
Patch Exists: NO
Related CWE:
CPE: a:ftppad:ftppad:1.2.0
Metasploit:
Other Scripts:
Platforms Tested: Windows
2010

FTPPad 1.2.0 Stack Buffer Overflow

This module exploits a stack buffer overflow FTPPad 1.2.0 ftp client. The overflow is triggered when the client connects to a FTP server which sends an overly long directory and filename in response to a LIST command. This will cause an access violation, and will eventually overwrite the saved extended instruction pointer. Payload can be found at EDX+5c and ESI+5c, so a little pivot/sniper was needed to make this one work.

Mitigation:

Update to a patched version of FTPPad.
Source

Exploit-DB raw data: