FreeFloat FTP Server
cpe:2.3:a:freefloat:freefloat_ftp_server:*:*:*:*:*:*:*
- 1.0
A critical buffer overflow vulnerability has been identified in FreeFloat FTP Server version 1.0. The issue arises in the DEBUG Command Handler component, where the application improperly validates the size of input buffers, allowing for remote exploitation. This vulnerability has been publicly disclosed and is known to impact the application's confidentiality, integrity, and availability.
Exploitation of this vulnerability leads to a buffer overflow, allowing for arbitrary code execution. The public exploit available demonstrates this by creating a reverse shell payload.
The vulnerability can be reproduced by sending an excessive amount of data through the 'DEBUG' command. This overload causes the application to crash, indicating a buffer overflow condition. After identifying the offset needed to exploit the vulnerability, the payload can be crafted to include a reverse shell payload, which is then sent to the server using the 'DEBUG' command.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.