CVE-2008-5106

KarjaSoft Sami FTP Server 2.0.x - Buffer Overflow via Long Command Argument

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-5106. PoCs published by superkojiman, including Metasploit module exploits/windows/ftp/sami_ftpd_list.

AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in Sami FTP Server 2.0.1 via a malformed LIST command. It requires the attacker to know or resolve the source IP address and for the victim to view the 'Log' tab in the managing application.

Description

Buffer overflow in KarjaSoft Sami FTP Server 2.0.x allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long argument to an arbitrary command, which triggers the overflow when the SamyFtp.binlog log file is viewed in the management console. NOTE: this may overlap CVE-2006-0441 and CVE-2006-2212.

Exploits (1)

metasploit WORKING POC LOW
by superkojiman · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/ftp/sami_ftpd_list.rb

This Metasploit module exploits a stack-based buffer overflow in Sami FTP Server 2.0.1 via a malformed LIST command. It requires the attacker to know or resolve the source IP address and for the victim to view the 'Log' tab in the managing application.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Sami FTP Server 2.0.1
No auth needed
Prerequisites: Target must be running Sami FTP Server 2.0.1 · Victim must view the 'Log' tab in the managing application · Attacker must know or resolve the source IP address
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/488198/100/200/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27817
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4603

Scores

EPSS 0.1259
EPSS Percentile 95.7%

Details

CWE
CWE-119
Status published
Products (3)
karjasoft/sami_ftp_server 2.0.0
karjasoft/sami_ftp_server 2.0.1
karjasoft/sami_ftp_server 2.0.2
Published Nov 17, 2008
Tracked Since Feb 18, 2026