vendor:
Xftp
by:
zombiefx
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Xftp
Affected Version From: Xftp 3.0 build 0238
Affected Version To: Xftp 3.0 build 0238
Patch Exists: NO
Related CWE:
CPE: a:netsarang:xftp:3.0
Platforms Tested: Windows XP SP3
2010
Xftp client 3.0 PWD Remote Exploit
The exploit occurs when sending an overly long PWD response. By sending a specially crafted response, an attacker can trigger a buffer overflow and potentially execute arbitrary code.
Mitigation:
Update to a patched version of Xftp client 3.0.