Description
FTPShell Server 6.83 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the account name field. Attackers can trigger a denial of service by pasting a 417-byte payload into the 'Account name to ban' parameter within the Manage FTP Accounts interface.
Problem types
Product status
Credits
Victor Mondragón
References
www.exploit-db.com/exploits/46430 (ExploitDB-46430)
www.ftpshell.com/index.htm (Official Product Homepage)
www.ftpshell.com/downloadserver.htm (Product Reference)
www.vulncheck.com/...rver-denial-of-service-via-account-name (VulnCheck Advisory: FTPShell Server 6.83 Denial of Service via Account Name)