Title: WS_FTP Server Multiple Command Remote Overflow
Info
Disclosure
Nov 29, 2004
Discovery
Unknown
Dates
Exploit
Nov 29, 2004
Solution
Unknown
Description
A buffer overflow exists in WSFTP. The SITE, XMKD, MKD, and RNFR commands fail to validate user-supplied arguments resulting in a stack overflow. With a specially crafted command, an authenticated user can cause arbitrary code execution in the context of the FTP server resulting in a loss of integrity.