CVE-2008-3734
Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 - Format String Vulnerability via FTP Server Greeting
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3734. PoCs published by securfrog.
AI-analyzed exploit summary This exploit demonstrates a remote format string vulnerability in Ipswitch WS_FTP Home/Professional FTP client. The PoC sets up a fake FTP server that sends a crafted response containing format string specifiers, allowing control over EAX/ECX registers and potentially leading to arbitrary code execution.
Description
Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP servers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in a connection greeting (response).
Exploits (1)
This exploit demonstrates a remote format string vulnerability in Ipswitch WS_FTP Home/Professional FTP client. The PoC sets up a fake FTP server that sends a crafted response containing format string specifiers, allowing control over EAX/ECX registers and potentially leading to arbitrary code execution.