vendor:
FTP Server
by:
Jacob Holcomb/Gimppy
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: FTP Server
Affected Version From: 2.0.7
Affected Version To: 2.0.7
Patch Exists: NO
Related CWE: Pending
CPE: a:pcman:ftp_server:2.0.7
Platforms Tested:
2013
PCMan FTP Server v2.0.7 Remote Root Shell Exploit – USER Command
Exploit allows for remote root shell access on PCMan FTP Server v2.0.7 using the USER command. Discovered and reported in June 2013 by Jacob Holcomb/Gimppy, a Security Analyst at Independent Security Evaluators. The exploit is available at http://infosec42.blogspot.com/. The vulnerability is a buffer overflow in the PCMan FTP Server v2.0.7 software, which listens on TCP/21. Only the USER command was tested, and the CVE is pending.
Mitigation:
Apply the latest patches and updates from the vendor. Consider using a different FTP server software if possible.