Description
Core FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash the application by supplying oversized input. Attackers can generate a 7000-byte payload of repeated 'A' characters to trigger an application crash without requiring additional interaction.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Berat Isler
References
www.exploit-db.com/exploits/48100 (ExploitDB-48100)
www.coreftp.com/ (Core FTP Official Homepage)
www.vulncheck.com/...ies/core-ftp-lite-denial-of-service-poc (VulnCheck Advisory: Core FTP Lite 1.3 - Denial of Service (PoC))