CVE-2008-5754

BulletProof FTP Client - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2008-5754. PoCs published by Rafa De Sousa, His0k4, Stack.

AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in BulletProof FTP Client v2.63 build 56 by crafting a malicious session file (.bps) that triggers an SEH overwrite. The PoC generates a file with a controlled payload to achieve arbitrary code execution.

Description

Stack-based buffer overflow in BulletProof FTP Client allows user-assisted attackers to execute arbitrary code via a .bps file (aka Session-File) with a long second line, possibly a related issue to CVE-2008-5753.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Rafa De Sousa · cremotewindows
https://www.exploit-db.com/exploits/9998

This exploit demonstrates a buffer overflow vulnerability in BulletProof FTP Client v2.63 build 56 by crafting a malicious session file (.bps) that triggers an SEH overwrite. The PoC generates a file with a controlled payload to achieve arbitrary code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: BulletProof FTP Client v2.63 build 56
No auth needed
Prerequisites: Ability to deliver a malicious .bps file to the target · Target must open the file in BulletProof FTP Client
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by His0k4 · pythonlocalwindows
https://www.exploit-db.com/exploits/8420

This exploit targets a buffer overflow vulnerability in BulletProof FTP Client 2009 via a malformed .bps session file. It leverages SEH overwrite with a jump to shellcode, executing a calc.exe payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: BulletProof FTP Client 2009
No auth needed
Prerequisites: Victim must open the malicious .bps file in BulletProof FTP Client 2009
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Stack · perldoswindows
https://www.exploit-db.com/exploits/7589

This exploit generates a malformed BulletProof FTP Client session file (.bps) with a long string of 'A' characters to trigger a local stack overflow. The PoC creates a file named 'Stack.bps' that, when loaded, causes the application to crash due to buffer overflow.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: BulletProof FTP Client (version not specified)
No auth needed
Prerequisites: Ability to write a file to the local filesystem · Victim must open the malformed .bps file in BulletProof FTP Client
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7589
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33024
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8420

Scores

EPSS 0.0458
EPSS Percentile 90.4%

Details

CWE
CWE-119
Status published
Products (1)
bpftp/bulletproof_ftp_client _nil_
Published Dec 30, 2008
Tracked Since Feb 18, 2026