Golden FTP Server Pro Multiple Command Remote Overflow DoS

medium Nessus Plugin ID 21325

Synopsis

The remote FTP server is affected by a buffer overflow flaw.

Description

The remote host appears to be using Golden FTP Server, a personal FTP server for Windows.

The version of Golden FTP Server installed on the remote host contains a buffer overflow vulnerability that can be exploited by an authenticated, possibly anonymous, user with a specially crafted NLST command to crash the affected application or execute arbitrary code on the affected host.

Solution

Unknown at this time.

See Also

https://seclists.org/bugtraq/2006/May/22

Plugin Details

Severity: Medium

ID: 21325

File Name: golden_ftp_server_nlst_overflow.nasl

Version: 1.20

Type: remote

Family: FTP

Published: 5/4/2006

Updated: 11/15/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.0

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Information

CPE: cpe:/a:kmint21_software:golden_ftp_server

Required KB Items: ftp/login, ftp/password

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 5/1/2006

Reference Information

CVE: CVE-2006-2180

BID: 17801

CWE: 119