Description
PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted payload during the FTP login process to overwrite memory and potentially gain system access.
Problem types
CWE-121 Stack-based Buffer Overflow
Product status
2.0
Credits
Waqas Ahmed Faroouqi (ZEROXINN)
References
www.exploit-db.com/exploits/51767 (ExploitDB-51767)
sourceforge.net/projects/pcmanftpd/ (PCMan FTP Server Sourceforge Page)
www.vulncheck.com/...-remote-buffer-overflow-via-pwd-command (VulnCheck Advisory: PCMan FTP Server 2.0 Remote Buffer Overflow via 'pwd' Command)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.