CVE-2005-1812
FutureSoft TFTP Server Evaluation Version 1.0.0.1 - Remote Code Execution via Long Filename or Transfer Mode String
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2005-1812.
PoCs published by Metasploit, ATmaCA, including Metasploit module exploits/windows/tftp/futuresoft_transfermode.
AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in FutureSoft TFTP Server 2000 via an overly long transfer-mode string, overwriting SEH and EIP to execute arbitrary shellcode. It targets multiple Windows versions and leverages UDP for delivery.
Description
Multiple stack-based buffer overflows in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allow remote attackers to execute arbitrary code via a long (1) filename or (2) transfer mode string in a Read Request (RRQ) or Write Request (WRQ) packet.
Exploits (3)
This Metasploit module exploits a stack buffer overflow in FutureSoft TFTP Server 2000 via an overly long transfer-mode string, overwriting SEH and EIP to execute arbitrary shellcode. It targets multiple Windows versions and leverages UDP for delivery.
This exploit targets a buffer overflow vulnerability in FutureSoft TFTP Server 2000 by sending a maliciously crafted RRQ (Read Request) packet with an overly long filename, leading to a denial of service (DoS). The payload is designed to overwrite the EIP register, though no shellcode is included for remote code execution.
This Metasploit module exploits a stack buffer overflow in FutureSoft TFTP Server 2000 via an overly long transfer-mode string, overwriting SEH and EIP to achieve remote code execution. It includes multiple targets for different Windows versions and leverages UDP for payload delivery.