PT-2006-3008 · Pablo Software Solutions · Quick 'N Easy Ftp Server
C0D3R
+1
·
Published
2006-04-26
·
Updated
2018-10-18
·
CVE-2006-2027
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Pablo Software Solutions Quick 'n Easy FTP Server Professional and Lite version 3.0
Description
The issue is related to a buffer overflow in Unicode processing within the logging functionality. This can be triggered by sending a command with a long argument, which then causes a buffer overflow when an admin selects the Logging section in the FTP server main window, potentially allowing remote authenticated users to execute arbitrary code.
Recommendations
For version 3.0, consider disabling the logging functionality until a fix is available to prevent potential exploitation. Restrict access to the FTP server main window's Logging section to minimize the risk of triggering the buffer overflow. Avoid using long arguments in commands to the FTP server to reduce the likelihood of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Quick 'N Easy Ftp Server