6.8
CVSSv2

CVE-2012-5002

Published: 19/09/2012 Updated: 29/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 690
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file name option is enabled, allows remote malicious users to execute arbitrary code via a long USER FTP command.

Vulnerable Product Search on Vulmon Subscribe to Product

ricoh dl-10 4.5.0.1

ricoh sr10 ftp server 1.1.0.6

Exploits

## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' class Metasploit3 < Msf::Exploit::Remote Rank = NormalRanking inc ...
#!/usr/bin/python # Exploit Title: Ricoh DC Software DL-10 FTP Server (SR10exe) <= 1106 Remote Buffer Overflow Vulnerability # Version: <= 1106 # Date: 2012-02-05 # Author: Julien Ahrens # Homepage: wwwinshellnet # Software Link: wwwricohpmmccom # Tested on: Windows XP SP3 Professional German ...