vendor:
i-FTP
by:
metacom and Gabor Seljan
7.5
CVSS
HIGH
Stack-based buffer overflow
119
CWE
Product Name: i-FTP
Affected Version From: i-FTP v2.20
Affected Version To: i-FTP v2.20
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2014
i-FTP Schedule Buffer Overflow
This module exploits a stack-based buffer overflow vulnerability in i-Ftp v2.20, caused by a long time value set for scheduled download. By persuading the victim to place a specially-crafted Schedule.xml file in the i-FTP folder, a remote attacker could execute arbitrary code on the system or cause the application to crash. This module has been tested successfully on Windows XP SP3.
Mitigation:
Update to the latest version of i-FTP