CVE-2009-1675
ElectraSoft 32bit FTP 09.04.24 - Remote Code Execution via Long PASV Reply
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-1675.
PoCs published by His0k4, fancy, including Metasploit module exploits/windows/ftp/32bitftp_list_reply.
AI-analyzed exploit summary This Metasploit module exploits a buffer overflow in the 32bit FTP client (version 09.04.24) via an excessively long PASV reply command. It delivers a reverse TCP payload to achieve remote code execution on vulnerable Windows systems.
Description
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 227 reply to a PASV command.
Exploits (2)
This Metasploit module exploits a buffer overflow in the 32bit FTP client (version 09.04.24) via an excessively long PASV reply command. It delivers a reverse TCP payload to achieve remote code execution on vulnerable Windows systems.
This Metasploit module exploits a stack buffer overflow in the 32bit FTP client (CVE-2009-1675) by sending a maliciously crafted filename during a LIST command, triggering remote code execution via an egg hunter and payload.