CVE-2006-2212
KarjaSoft Sami FTP Server <= 2.0.2 - Remote Code Execution via Long USER or PASS Command
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-2212.
PoCs published by Metasploit, Muhammad Ahmed Siddiqui, Critical Security, n30m1nd, aushack, bcoles, including Metasploit module exploits/windows/ftp/sami_ftpd_user.
AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in KarjaSoft Sami FTP Server v2.02 via an excessively long USER command. The exploit is passive, requiring administrator interaction to view FTP logs for execution.
Description
Buffer overflow in KarjaSoft Sami FTP Server 2.0.2 and earlier allows remote attackers to execute arbitrary code via a long (1) USER or (2) PASS command.
Exploits (2)
This Metasploit module exploits a stack-based buffer overflow in KarjaSoft Sami FTP Server v2.02 via an excessively long USER command. The exploit is passive, requiring administrator interaction to view FTP logs for execution.
This Metasploit module exploits an unauthenticated stack buffer overflow in KarjaSoft Sami FTP Server v2.0.2 via an overly long USER string during login, achieving remote code execution when the administrator opens the GUI.