7.5
CVSSv2

CVE-2007-0338

Published: 18/01/2007 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in Dream FTP Server allows remote malicious users to execute arbitrary code via a USER command with a large number of format string specifiers, which triggers the overflow during processing of the Server Log.

Vulnerable Product Search on Vulmon Subscribe to Product

bolintech dreamftp server

Exploits

/************************************************************************** *BolinTech DreamFTP USER buffer overflow * * * *The server does not correctly handle format string so sending a command * *like USER %1*3000 let us own EDX Other value ...