7.5
CVSSv2

CVE-2006-6576

Published: 15/12/2006 Updated: 16/03/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote malicious users to cause a denial of service (application crash) and possibly execute arbitrary code via a long PASS command. NOTE: it was later reported that 4.70 is also affected. NOTE: the USER vector is already covered by CVE-2005-0634.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

goldenftpserver golden ftp server 1.92

Exploits

# # $Id: goldenftp_pass_bofrb 12812 2011-06-02 01:10:22Z bannedit $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' ...
#GoldenFTP 470 PASS Exploit #Authors: Craig Freyman (cd1zz) and Gerardo Iglesias Galvan (iglesiasgg) #Tested on XP SP3 #Vendor Contacted: 1/17/2011 (no response) #For this exploit to work correctly, you need to know the subnet that the server #is running on You also need to make sure that "show new connections" is checked in the options #The t ...