vendor:
PCMan's FTP Server
by:
Koby
9
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: PCMan's FTP Server
Affected Version From: 2
Affected Version To: 2.0.7
Patch Exists: YES
Related CWE:
CPE: a:pcman:pcman's_ftp_server:2.0
Platforms Tested: Windows XP SP3
2015
PCMan’s FTP Server v2.0 – GET command buffer overflow (remote shell)
The PCMan's FTP Server version 2.0 is vulnerable to a buffer overflow in the GET command, which can allow remote code execution and result in a remote shell. This can be exploited by sending a specially crafted GET command with a large payload, causing a buffer overflow and overwriting the return address. This exploit has been tested on Windows XP SP3.
Mitigation:
The vendor has released a patch for this vulnerability. It is recommended to update to the latest version of PCMan's FTP Server.