CVE-2011-3976
MEDIUM 6.8EPSS 30.6%
Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long filename in a response to a LIST command, as demonstrated using (1) GETLIST or (2) GETFILE in a ScriptFTP script.
- CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 30.59% chance of exploitation in the next 30 days, 98th percentile
- Published
- 2011-10-04
- Updated
- 2024-08-06
Proof-of-concept exploits (2)
- http://www.exploit-db.com/exploits/17876
- http://www.digital-echidna.org/2011/09/scriptftp-3-3-remote-buffer-overflow-exploit-0day/
Metasploit modules (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/17948
- https://www.exploit-db.com/exploits/17876
- https://www.exploit-db.com/exploits/17904