CVE-2005-1415

GlobalSCAPE Secure FTP Server 3.0.2 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2005-1415. PoCs published by Metasploit, muts, including Metasploit module exploits/windows/ftp/globalscapeftp_input.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in GlobalSCAPE Secure FTP Server versions prior to 3.0.3. It sends a maliciously crafted input to trigger the overflow and execute arbitrary payloads.

Description

Buffer overflow in GlobalSCAPE Secure FTP Server 3.0.2 allows remote authenticated users to execute arbitrary code via a long FTP command.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16703

This exploit targets a buffer overflow vulnerability in GlobalSCAPE Secure FTP Server versions prior to 3.0.3. It sends a maliciously crafted input to trigger the overflow and execute arbitrary payloads.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: GlobalSCAPE Secure FTP Server <= 3.0.2
Auth required
Prerequisites: Valid user account or anonymous access · Network access to the FTP server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by muts · pythonremotewindows
https://www.exploit-db.com/exploits/975

This exploit targets a buffer overflow vulnerability in GlobalScape Secure FTP Server v3.0. It sends a crafted payload to overwrite EIP and execute a bind shell on port 4444.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: GlobalScape Secure FTP Server v3.0
Auth required
Prerequisites: Network access to the FTP server · Valid credentials for authentication
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GREAT
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/ftp/globalscapeftp_input.rb

This Metasploit module exploits a buffer overflow in GlobalSCAPE Secure FTP Server versions prior to 3.0.3. It sends a maliciously crafted input to trigger a stack-based overflow, allowing arbitrary code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: GlobalSCAPE Secure FTP Server <= 3.0.2
Auth required
Prerequisites: Valid user account or anonymous access · Network access to the FTP server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/13454
Patch x_refsource_confirm
http://www.cuteftp.com/gsftps/history.asp

Scores

EPSS 0.6046
EPSS Percentile 99.0%

Details

Status published
Products (2)
globalscape/secure_ftp_server 3.0
globalscape/secure_ftp_server 3.0.2
Published May 03, 2005
Tracked Since Feb 18, 2026