PCMan FTP Server Buffer Overflow Vulnerability in SYSTEM Command Handler

Vulnerability

A critical buffer overflow vulnerability has been identified in PCMan FTP Server version 2.0.7. The issue arises in an unknown function of the SYSTEM Command Handler component, allowing remote exploitation. The vulnerability was disclosed publicly and is actively being exploited.

Impact

Exploitation of this vulnerability leads to a buffer overflow, allowing for arbitrary code execution. In this case, the exploitation was demonstrated by executing a reverse shell payload, providing the attacker with remote access to the affected system.

Reproduction

The vulnerability can be reproduced by sending an excessive amount of data through the 'SYSTEM' command, which causes the application to crash, indicating a buffer overflow. After confirming the vulnerability, the exploitation involves overwriting the Extended Instruction Pointer (EIP) with a return address that points to a payload, such as a reverse shell, which is then executed with the privileges of the FTP server process.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
10.0
exploitability
9.7
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.