PT-2006-3149 · Argosoft · Argosoft Ftp Server

Leon Juranic

·

Published

2006-05-04

·

Updated

2017-07-20

·

CVE-2006-2170

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions ArgoSoft FTP Server version 1.4.3.6
Description The issue allows remote attackers to execute arbitrary code via Unicode in the RNTO command. This can be demonstrated using tools like the Infigo FTPStress Fuzzer.
Recommendations For ArgoSoft FTP Server version 1.4.3.6, consider disabling the RNTO command until a patch is available to prevent potential exploitation. Restrict access to the server to minimize the risk of arbitrary code execution.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2170

Affected Products

Argosoft Ftp Server