5
CVSSv2

CVE-2004-1626

Published: 22/10/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 510
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote malicious users to execute arbitrary code via a long STOR command.

Vulnerable Product Search on Vulmon Subscribe to Product

code-crafters ability server 2.2.5

code-crafters ability server 2.3.2

code-crafters ability server 2.3.4

Exploits

/* no@0x00:~/Exploits/abilityftp$ /ability-exploit **Ability Server 234 Remote buffer overflow exploit in ftp STOR by NoPh0BiA** [x] Launching listener [x] Bind successfull [x] Listening on port 31337 [x] Connected to: 19216801 [x] Sending bad codedone [x] Waiting for shell [x] Got connection from 19216801 [x] 0wn3d! Microsoft W ...
################################### # Ability Server 234 FTP STOR Buffer Overflow # # Advanced, secure and easy to use FTP Server # # 21 Oct 2004 - muts # ################################### # D:\BO>ability-234-ftp-storpy # ################################### # D:\data\tools>nc ...