788Third-party advisory
http://securityreason.com/securityalert/788 CVE-2006-2027
Quick 'n EasY 2.4 FTP Server - Remote Denial of Service
Record summary
CVE-2006-2027 has a selected CVSS score of 6.5; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in Unicode processing in the logging functionality in Pablo Software Solutions Quick 'n Easy FTP Server Professional and Lite, probably 3.0, allows remote authenticated users to execute arbitrary code by sending a command with a long argument, which triggers a buffer overflow when an admin selects the Logging section in the FTP server main window. NOTE: the original researcher claims that the vendor disputes this issue.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBQuick 'n EasY 2.4 FTP Server - Remote Denial of ServiceExploitDB exploitby KaGraNot analyzed1 file
References
525235vdb entry
http://www.osvdb.org/25235 20060424 Quick 'n Easy FTP Server pro/lite Logging unicode stack overflowmailing list
http://www.securityfocus.com/archive/1/431920/100/0/threaded 17681vdb entry
http://www.securityfocus.com/bid/17681 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-2027