vendor:
FTPShell Server
by:
Hashim Jawad
7.5
CVSS
HIGH
Local Buffer Overflow
Buffer Overflow
CWE
Product Name: FTPShell Server
Affected Version From: FTPShell Server v6.80
Affected Version To: FTPShell Server v6.80
Patch Exists: NO
Related CWE:
CPE: a:ftpshell:ftpshell_server:6.80
Platforms Tested: Windows XP Professional SP3
FTPShell Server v6.80 – Local Buffer Overflow (SafeSEH Bypass)
The exploit allows for a local buffer overflow in FTPShell Server v6.80, bypassing SafeSEH protection. By pasting the contents of Evil.txt in the 'Password' field under configure accounts>Change pass, an attacker can execute arbitrary code.
Mitigation:
Update to a patched version of FTPShell Server that fixes the buffer overflow vulnerability.