CVE-2008-4726
GoodTech SSH 6.4 - Authenticated Stack-Based Buffer Overflow via SFTP Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4726. PoCs published by r0ut3r.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in GoodTech SSH server via the SSH_FXP_OPEN command. It sends a crafted payload containing a NOP sled and shellcode to achieve remote code execution.
Description
Stack-based buffer overflow in the SFTP subsystem in GoodTech SSH 6.4 allows remote authenticated users to execute arbitrary code via a long string to the (1) open (aka SSH_FXP_OPEN), (2) unlink, (3) opendir, and other unspecified parameters.
Exploits (1)
This exploit targets a buffer overflow vulnerability in GoodTech SSH server via the SSH_FXP_OPEN command. It sends a crafted payload containing a NOP sled and shellcode to achieve remote code execution.