7.2
CVSSv2

CVE-2005-1371

Published: 03/05/2005 Updated: 11/07/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

BPFTPServer service in BulletProof FTP Server 2.4.0.31 does not properly drop privileges before opening files through the Help menu, which allows local users to gain privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

bulletproof bulletproof ftp server 2.4.0.31

Exploits

//****************************************************************************** //Privilege escalation in BulletProof FTP Server v24031 //By Jerome Athias //jerome DOT athias AT free DOT fr //Discovered by Reed Arvin reedarvin[at]gmail[dot]com //(reedarvinthearvinscom) // //Little PoC //Gives you a shell with system privileges //****** ...