vendor:
FTP
by:
Mahmod Mahajna
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: FTP
Affected Version From: 02.07
Affected Version To: 02.07
Patch Exists: NO
Related CWE:
CPE: a:pcman:ftp:2.07
Platforms Tested: Windows 7 sp1 x64
2014
PCMAN FTP 2.07 ABOR Command Buffer Overflow
This exploit takes advantage of a buffer overflow vulnerability in the ABOR command of PCMAN FTP 2.07. By sending a specially crafted payload, an attacker can overwrite the function pointer and gain control of the program. The exploit includes a bind shell on port 4444.
Mitigation:
Apply the latest patch from the vendor.