vendor:
WFTPD Explorer Pro
by:
r4x (Kamil Szczerba)
7.5
CVSS
HIGH
Heap Overflow
119
CWE
Product Name: WFTPD Explorer Pro
Affected Version From: WFTPD Explorer Pro 1.0
Affected Version To: WFTPD Explorer Pro 1.0
Patch Exists: NO
Related CWE:
CPE: a:texas_imperial_software:wftpd_explorer_pro:1.0
Platforms Tested: Windows XP SP2 (Polish)
WftpdExpPro_HeapPoC.py
This is a proof of concept (PoC) exploit for a heap overflow vulnerability in the WFTPD Explorer Pro 1.0 software. The exploit allows an attacker to overwrite a register in the application's memory, causing an access violation (c0000005). The exploit uses a crafted payload to trigger the vulnerability.
Mitigation:
The vendor should release a patch that fixes the heap overflow vulnerability. In the meantime, users should consider disabling or uninstalling the affected software.