CVE-2018-7573
CRITICALFTPShell Client 6.7 - Remote Code Execution via FTP 220 Response Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2018-7573.
PoCs published by Metasploit, r4wd3r, r4wd3r, Daniel Teixeira, including Metasploit module exploits/windows/ftp/ftpshell_cli_bof.
AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in FTPShell Client 6.70 (Enterprise edition) via a malicious FTP server response, leading to remote code execution. The exploit leverages a controlled return address to execute arbitrary payloads.
Description
An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with the FTP 220 response code to crash the application; after this overflow, one can run arbitrary code on the victim machine. This is similar to CVE-2009-3364 and CVE-2017-6465.
Exploits (3)
This Metasploit module exploits a stack buffer overflow in FTPShell Client 6.70 (Enterprise edition) via a malicious FTP server response, leading to remote code execution. The exploit leverages a controlled return address to execute arbitrary payloads.
This exploit targets a buffer overflow vulnerability in FTPShell Client 6.7 by sending a maliciously crafted payload to trigger remote code execution. The payload includes shellcode generated by msfvenom to spawn calc.exe.
This Metasploit module exploits a stack buffer overflow in FTPShell client 6.70 (Enterprise edition) by sending a malicious FTP response containing shellcode. It sets up a fake FTP server to trigger the vulnerability when the client connects.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H