CVE-2010-20108
HIGHFTPPad <= 1.2.0 - Stack-based Buffer Overflow via FTP LIST Response
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2010-20108.
PoCs published by Metasploit, corelanc0d3r, including Metasploit module exploits/windows/ftp/ftppad_list_reply.
AI-analyzed exploit summary This exploit targets a stack buffer overflow in FTPPad 1.2.0 by sending an overly long directory and filename in response to a LIST command. It leverages a pivot/sniper technique to execute payload located at EDX+5c and ESI+5c.
Description
FTPPad <= 1.2.0 contains a stack-based buffer overflow vulnerability in its FTP directory listing parser. When the client connects to an FTP server and receives a crafted response to a LIST command containing an excessively long directory and filename, the application fails to properly validate input length. This results in a buffer overflow that overwrites the saved Extended Instruction Pointer (EIP), allowing remote attackers to execute arbitrary code.
Exploits (2)
This exploit targets a stack buffer overflow in FTPPad 1.2.0 by sending an overly long directory and filename in response to a LIST command. It leverages a pivot/sniper technique to execute payload located at EDX+5c and ESI+5c.
This Metasploit module exploits a stack buffer overflow in FTPPad 1.2.0 by sending an overly long directory listing in response to a LIST command, leading to arbitrary code execution via a carefully crafted payload and pivot technique.
References (5)
Scores
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N