46781Third-party advisory
http://secunia.com/advisories/46781 CVE-2011-5164
AbsoluteFTP 1.9.6 < 2.2.10 - 'LIST' Remote Buffer Overflow (Metasploit)
Record summary
CVE-2011-5164 has a selected CVSS score of 9.3; EIP currently links 2 catalogued exploits.
Description
Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute arbitrary code via a crafted file name in a LIST command response.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBAbsoluteFTP 1.9.6 < 2.2.10 - 'LIST' Remote Buffer Overflow (Metasploit)ExploitDB exploitby NodeNot analyzed1 file
MetasploitAbsoluteFTP 1.9.6 - 2.2.10 LIST Command Remote Buffer OverflowMetasploit exploitby NodeNot analyzed1 file
References
618102exploit
http://www.exploit-db.com/exploits/18102 77105vdb entry
http://www.osvdb.org/77105 saintcorporation.com
http://www.saintcorporation.com/cgi-bin/exploit_info/vandyke_absoluteftp_list_client_overflow 50614vdb entry
http://www.securityfocus.com/bid/50614 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2011-5164