20090120 Re: Remote Cisco IOS FTP exploitmailing list
http://seclists.org/bugtraq/2009/Jan/0183.html CVE-2007-2586
Cisco IOS 12.3(18) (FTP Server) - Remote (Attached to GDB)
Record summary
CVE-2007-2586 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCisco IOS 12.3(18) (FTP Server) - Remote (Attached to GDB)ExploitDB exploitby Andy DavisNot analyzed1 file
References
1225199Third-party advisory
http://secunia.com/advisories/25199 20070509 Multiple Vulnerabilities in the IOS FTP ServerVendor advisory
http://www.cisco.com/en/US/products/products_security_advisory09186a00808399d0.shtml 6155exploit
http://www.exploit-db.com/exploits/6155 35334vdb entry
http://www.osvdb.org/35334 20080729 Remote Cisco IOS FTP exploitmailing list
http://www.securityfocus.com/archive/1/494868 23885vdb entry
http://www.securityfocus.com/bid/23885 1018030vdb entry
http://www.securitytracker.com/id?1018030 ADV-2007-1749vdb entry
http://www.vupen.com/english/advisories/2007/1749 cisco-ios-ftp-unauthorized-access(34197)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/34197 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-2586 oval:org.mitre.oval:def:5036vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5036