CVE-2011-5166

KnFTP 1.0.0 - Remote Code Execution via Multiple Stack-Based Buffer Overflows

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2011-5166. PoCs published by mr.pr0n, loneferret, blake.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in KnFTP 1.0.0 Server via the 'USER' command. It uses an egghunter and shellcode to execute calc.exe, leveraging a JMP ESP instruction in kernel32.dll.

Description

Multiple stack-based buffer overflows in KnFTP 1.0.0 allow remote attackers to execute arbitrary code via a long string to the (1) USER, (2) PASS, (3) REIN, (4) QUIT, (5) PORT, (6) PASV, (7) TYPE, (8) STRU, (9) MODE, (10) RETR, (11) STOR, (12) APPE, (13) ALLO, (14) REST, (15) RNFR, (16) RNTO, (17) ABOR, (18) DELE, (19) CWD, (20) LIST, (21) NLST, (22) SITE, (23) STST, (24) HELP, (25) NOOP, (26) MKD, (27) RMD, (28) PWD, (29) CDUP, (30) STOU, (31) SNMT, (32) SYST, and (33) XPWD commands.

Exploits (4)

exploitdb WORKING POC VERIFIED
by mr.pr0n · perlremotewindows
https://www.exploit-db.com/exploits/17870

This exploit targets a buffer overflow vulnerability in KnFTP 1.0.0 Server via the 'USER' command. It uses an egghunter and shellcode to execute calc.exe, leveraging a JMP ESP instruction in kernel32.dll.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: KnFTP Server 1.0.0
No auth needed
Prerequisites: Network access to the target FTP server · KnFTP 1.0.0 Server running on Windows XP SP3
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by loneferret · pythondoswindows
https://www.exploit-db.com/exploits/17856

This exploit demonstrates a buffer overflow vulnerability in KnFTP Server by sending an overly long string (9000 'A' characters) via the PWD command, causing a denial-of-service (DoS) condition. The PoC includes register states showing SEH/EIP overwrites, confirming the vulnerability.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: KnFTP Server (version not specified)
Auth required
Prerequisites: Network access to the KnFTP Server · Valid FTP credentials (USER/PASS)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by blake · pythonremotewindows
https://www.exploit-db.com/exploits/17819

This exploit targets a buffer overflow vulnerability in KnFTP server by sending a maliciously crafted PASS command. It uses an egghunter technique to locate and execute shellcode, which spawns calc.exe as a proof of concept.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: KnFTP Server (version not specified)
No auth needed
Prerequisites: Network access to the target KnFTP server · KnFTP server running on a vulnerable Windows system (e.g., Windows XP SP3)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by pasta · rubyremotewindows
https://www.exploit-db.com/exploits/18089

This Metasploit module exploits a buffer overflow vulnerability in KnFTP FTP Server to achieve remote code execution by bypassing DEP via ROP chains. It targets specific Windows versions (XP SP2/SP3 and Windows 7 SP1) with tailored ROP gadgets.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: KnFTP FTP Server
No auth needed
Prerequisites: Network access to vulnerable KnFTP server · Target system must be running a vulnerable version of KnFTP
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/45907
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/17856
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2011-09/0015.html
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18089
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/69557
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/75147
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/17819
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/17870

Scores

EPSS 0.4179
EPSS Percentile 97.5%

Details

CWE
CWE-119
Status published
Products (1)
elif_keir/knftp 1.0.0
Published Sep 15, 2012
Tracked Since Feb 18, 2026