FTP Commander Pro Stack Overflow Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A local stack overflow vulnerability has been identified in FTP Commander Pro versions 8.02 and 8.03. This vulnerability allows attackers to execute arbitrary code by overwriting the EIP register through custom command input. By crafting a malicious payload of 4108 bytes, attackers can overwrite memory, execute shellcode, and potentially execute remote code.

Impact

Exploitation of this vulnerability leads to a stack-based buffer overflow, allowing for arbitrary code execution.

Reproduction

To reproduce this vulnerability, open FTP Commander Pro and navigate to the 'Custom Command' option under the 'FTP - Server' menu. A textbox will appear where the crafted payload can be pasted. After submitting the command, the application will crash, indicating an access violation. The Exploit Database entry for this vulnerability provides a detailed Python script that automates the payload generation and exploitation process.

Added: Feb 12, 2026, 11:26 PM
Updated: Feb 12, 2026, 11:26 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
7.5
exploitability
5.0
remediation
7.7
relevance
3.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.