CVE-2024-0546
MEDIUMEasyFTP 1.7.0 - Denial of Service via LIST Command Handler
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-0546.
Includes Metasploit module exploits/windows/ftp/easyftp_list_fixret.
AI-analyzed exploit summary This Metasploit module exploits a stack-based buffer overflow in EasyFTP Server 1.7.0.11 via the LIST command. It uses a fix-up stub to handle larger payloads and achieves remote code execution by overwriting the return address.
Description
A vulnerability, which was classified as problematic, has been found in EasyFTP 1.7.0. This issue affects some unknown processing of the component LIST Command Handler. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250715.
Exploits (1)
This Metasploit module exploits a stack-based buffer overflow in EasyFTP Server 1.7.0.11 via the LIST command. It uses a fix-up stub to handle larger payloads and achieves remote code execution by overwriting the return address.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L