Exploitation Summary
EIP tracks 2 public exploits for CVE-2007-1195. PoCs published by mr_me, Umesh Wanve.
AI-analyzed exploit summary This exploit leverages a format string vulnerability in XM Easy Personal FTP Server to overwrite a vtable pointer, leading to arbitrary code execution via a ROP chain. It includes shellcode for a bind shell and is tested against specific Windows environments.
Description
Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unspecified vectors. NOTE: this issue might overlap CVE-2006-2225, CVE-2006-2226, or CVE-2006-5728.
Exploits (2)
This exploit leverages a format string vulnerability in XM Easy Personal FTP Server to overwrite a vtable pointer, leading to arbitrary code execution via a ROP chain. It includes shellcode for a bind shell and is tested against specific Windows environments.
This exploit demonstrates a format string vulnerability in XM Easy Personal FTP Server 5.3.0. It sends a crafted string with multiple '%n' format specifiers via the ABOR command, causing the server to crash.