vendor:
FTPShell Server
by:
Greg Priest
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: FTPShell Server
Affected Version From: 6.56
Affected Version To: 6.56
Patch Exists: YES
Related CWE: N/A
CPE: a:ftpshell_software:ftpshell_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows7 x64 HUN/ENG Enterprise
2017
FTPShell Server 6.56 ChangePassword DEP off BufferOverflow 0Day
FTPShell Server 6.56 is vulnerable to a buffer overflow vulnerability when a maliciously crafted string is sent to the ChangePassword function. This can be exploited to execute arbitrary code by overwriting the saved return address with a pointer to the shellcode.
Mitigation:
Disable DEP and apply the latest patch from the vendor.