vendor:
HP-UX ftpd
by:
babcia padlina ltd.
7,5
CVSS
HIGH
Buffer Overflow
120 (Buffer Copy without Checking Size of Input)
CWE
Product Name: HP-UX ftpd
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2000
HP-UX ftpd vulnerability exploit
This exploit is a theoretical exploit for HP-UX ftpd vulnerability. It is not tested anywhere and needs tweaking. It contains a HP-UX shellcode and a NOP sled. It also contains a buffer of size 1024 and a return address of 0xdeadbeef. It is used to send a PASS command with the shellcode and NOP sled to the ftpd server.
Mitigation:
The mitigation for this vulnerability is to ensure that the size of the input is checked before copying it to the buffer.