vendor:
KnFTP
by:
Blake
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: KnFTP
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2020
KnFTP Buffer Overflow
A buffer overflow vulnerability exists in KnFTP, which is a non-safeseh module. An attacker can exploit this vulnerability by sending a specially crafted payload of 271 bytes to the vulnerable server, which will overwrite the EIP and SEH registers. This can be used to execute arbitrary code on the vulnerable system.
Mitigation:
Upgrade to the latest version of KnFTP, or apply the appropriate patch.