CVE-2007-0020
Panic Transmit < 3.5.5 - Remote Code Execution via Long FTPS URL
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0020. PoCs published by MoAB.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in the handling of FTPS URLs in Internet Explorer. It constructs a malicious FTPS URL with a long string of 'A' characters followed by 'ABCD' to trigger the overflow when the iframe is loaded.
Description
Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote attackers to execute arbitrary code via a long ftps:// URL.
Exploits (1)
This exploit targets a buffer overflow vulnerability in the handling of FTPS URLs in Internet Explorer. It constructs a malicious FTPS URL with a long string of 'A' characters followed by 'ABCD' to trigger the overflow when the iframe is loaded.