vendor:
NICO-FTP
by:
Abdullah Alıç
7.8
CVSS
HIGH
Buffer Overflow (SEH)
119
CWE
Product Name: NICO-FTP
Affected Version From: 3.0.1.19
Affected Version To: 3.0.1.19
Patch Exists: YES
Related CWE: N/A
CPE: a:nico-ftp:nico-ftp:3.0.1.19
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows XP Professional SP3 x86 eng
2018
NICO-FTP 3.0.1.19 – Buffer Overflow (SEH)
A buffer overflow vulnerability exists in NICO-FTP 3.0.1.19, which could allow an attacker to execute arbitrary code on the target system. The vulnerability is due to a boundary error when handling user-supplied input. An attacker could exploit this vulnerability by sending a specially crafted request to the vulnerable application. This may allow the attacker to execute arbitrary code on the system with the privileges of the vulnerable application.
Mitigation:
Upgrade to the latest version of NICO-FTP 3.0.1.19 or apply the appropriate patch.