vendor:
Quick 'n Easy FTP Server Lite
by:
Sumit Sharma (aka b0nd)
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Quick 'n Easy FTP Server Lite
Affected Version From: 3.1
Affected Version To: 3.1
Patch Exists: YES
Related CWE: N/A
CPE: a:quick_and_easy_software_solutions:quick_'n_easy_ftp_server_lite
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2
2009
Quick ‘n Easy FTP Server Lite Version 3.1 Crash PoC
The LIST command in Version 3.1 of Quick 'n Easy FTP Server Lite is vulnerable. When sending a string of 232 A's followed by a '?' character, the server crashes. No SEH overwrite or EIP overwrite occurs.
Mitigation:
Upgrade to the latest version of Quick 'n Easy FTP Server Lite.