vendor:
Golden FTP server
by:
rgod
7,5
CVSS
HIGH
Heap-Based Buffer Overflow
119
CWE
Product Name: Golden FTP server
Affected Version From: 1.92
Affected Version To: 1.92
Patch Exists: YES
Related CWE: N/A
CPE: a:golden_ftp_server:golden_ftp_server:1.92
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2006
Golden FTP server 1.92 (freeware edition) USER/PASS heap based overflow poc
Golden FTP server 1.92 (freeware edition) is vulnerable to a heap-based buffer overflow when sending an overly long USER/PASS string. This can be exploited to execute arbitrary code by overwriting a structured exception handler (SEH) with a malicious payload.
Mitigation:
Upgrade to the latest version of Golden FTP server.