Exploitation Summary
EIP tracks 2 public exploits for CVE-2010-2701. PoCs published by Madjix, blake.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in FathFTP 1.8 ActiveX control via a crafted HTML page. It uses SEH overwrite with a calc.exe payload, leveraging Alpha2-encoded shellcode.
Description
Multiple buffer overflows in the FathFTP ActiveX control 1.7 allow remote attackers to execute arbitrary code via (1) the GetFromURL member or (2) a long argument to the RasIsConnected method.
Exploits (2)
This exploit targets a buffer overflow vulnerability in FathFTP 1.8 ActiveX control via a crafted HTML page. It uses SEH overwrite with a calc.exe payload, leveraging Alpha2-encoded shellcode.
This exploit targets a buffer overflow vulnerability in FathFTP 1.7 ActiveX control via the RasIsConnected method. It uses a crafted payload with SEH overwrite to achieve arbitrary code execution, delivering a calc.exe payload via Alpha2-encoded shellcode.