漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ComSndFTP v1.3.7 Beta USER Format String RCE
Vulnerability Description
ComSndFTP FTP Server version 1.3.7 Beta contains a format string vulnerability in its handling of the USER command. By sending a specially crafted username containing format specifiers, a remote attacker can overwrite a hardcoded function pointer in memory (specifically WSACleanup from Ws2_32.dll). This allows the attacker to redirect execution flow and bypass DEP protections using a ROP chain, ultimately leading to arbitrary code execution. The vulnerability is exploitable without authentication and affects default configurations.
CVSS Information
N/A
Vulnerability Type
使用外部控制的格式字符串
Vulnerability Title
ComSndFTP FTP Server 安全漏洞
Vulnerability Description
ComSndFTP FTP Server是ComSndFTP公司的一个FTP服务器软件。 ComSndFTP FTP Server 1.3.7 Beta版本存在安全漏洞,该漏洞源于处理USER命令时存在格式化字符串漏洞,可能导致执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A