PCMan FTP Server PUT buffer overflow

Added: 08/13/2015

Background

PCMan's FTP Server is a free FTP server for Windows.

Problem

A buffer overflow vulnerability in PCMan's FTP Server allows remote attackers to execute arbitrary commands.

Resolution

There is no known fix for this vulnerability. Use a different FTP server, or block access to port 21 at the firewall.

References

https://www.exploit-db.com/exploits/37731/

Limitations

Exploit works on PCMan's FTP Server 2.0.7 on Windows XP SP3.

Platforms

Windows XP

Back to exploit index