vendor:
XFTP
by:
sinn3r
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: XFTP
Affected Version From: XFTP 3.0 Build 0239
Affected Version To: XFTP 3.0 Build 0239
Patch Exists: YES
Related CWE: CVE-2010-1890
CPE: a:netsarang:xfpt:3.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 ENG
2010
XFTP 3.0 Build 0239 Long filename Buffer Overflow
XFTP 3.0 Build 0239 is vulnerable to a buffer overflow when handling a long filename retrieved using "LIST". An attacker can exploit this vulnerability by serving a malicious response as a FTP server, and tricking the victim into double clicking on the filename.
Mitigation:
Upgrade to XFTP 3.0 Build 0242 & 0243