9.3
CVSSv2

CVE-2011-5164

Published: 15/09/2012 Updated: 17/09/2012
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 up to and including 2.2.10 allows remote FTP servers to execute arbitrary code via a crafted file name in a LIST command response.

Vulnerable Product Search on Vulmon Subscribe to Product

vandyke absoluteftp 2.2.10

vandyke absoluteftp 2.2.1

vandyke absoluteftp 2.2.2

vandyke absoluteftp 2.2.3

vandyke absoluteftp 2.2.4

vandyke absoluteftp 2.2.5

vandyke absoluteftp 2.0.3

vandyke absoluteftp 2.0.5

vandyke absoluteftp 2.2.7

vandyke absoluteftp 2.2.9

vandyke absoluteftp 1.9.6

vandyke absoluteftp 2.0.4

vandyke absoluteftp 2.2.6

vandyke absoluteftp 2.2.8

Exploits

# Exploit Title: AbsoluteFTP 196 - 2210 Remote Buffer Overflow (LIST) # Date: 2011-11-09 # Author: Node # Software Link: wwwvandykecom/pub/AbsoluteFTP/aftp2210exe # Version: 196 - 2210 # Tested on: Windows XP SP3, Windows 7 SP1 # CVE : - # Exploit has been tested to work on: # AbsoluteFTP 2210 (build 252) # AbsoluteFTP 229 ( ...