CVE-2017-6465
CRITICALFTPShell Client 6.53 - Remote Code Execution via PWD Response Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2017-6465.
PoCs published by Peter Baris, including Metasploit module exploits/windows/ftp/ftpshell51_pwd_reply.
AI-analyzed exploit summary This exploit leverages a buffer overflow vulnerability in FTPShell Client 6.53 during the initial connection phase. It sets up a malicious FTP server that sends a crafted response containing shellcode and a manipulated EIP to achieve remote code execution.
Description
Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP server it is connecting to; however, it doesn't check the response's length, leading to a buffer overflow situation.
Exploits (2)
This exploit leverages a buffer overflow vulnerability in FTPShell Client 6.53 during the initial connection phase. It sets up a malicious FTP server that sends a crafted response containing shellcode and a manipulated EIP to achieve remote code execution.
This Metasploit module exploits a stack buffer overflow in FTPShell 5.1 by sending an overly long response to a PWD command, overwriting the saved EIP and structured exception handler to achieve remote code execution.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H