PCMan FTP Server
cpe:2.3:a:pcman_ftp_server_project:pcman_ftp_server:*:*:*:*:*:*:*
- 2.0.7
A critical buffer overflow vulnerability has been identified in PCMan FTP Server version 2.0.7. The issue arises in an unknown function of the SYSTEM Command Handler component, allowing remote exploitation. The vulnerability was disclosed publicly and is actively being exploited.
Exploitation of this vulnerability leads to a buffer overflow, allowing for arbitrary code execution. In this case, the exploitation was demonstrated by executing a reverse shell payload, providing the attacker with remote access to the affected system.
The vulnerability can be reproduced by sending an excessive amount of data through the 'SYSTEM' command, which causes the application to crash, indicating a buffer overflow. After confirming the vulnerability, the exploitation involves overwriting the Extended Instruction Pointer (EIP) with a return address that points to a payload, such as a reverse shell, which is then executed with the privileges of the FTP server process.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.