Vulnerability Description
FTP Commander Pro 8.03 contains a local stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting the EIP register through a custom command input. Attackers can craft a malicious payload of 4108 bytes to overwrite memory and execute shellcode, demonstrating remote code execution potential.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- http://www.internet-soft.com/
- https://www.exploit-db.com/exploits/37810
- https://www.exploit-db.com/exploits/47775
- https://www.vulncheck.com/advisories/ftp-commander-pro-local-stack-overflow
FAQ
What is CVE-2019-25332?
CVE-2019-25332 is a vulnerability with a CVSS score of 8.4 (HIGH). FTP Commander Pro 8.03 contains a local stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting the EIP register through a custom command input. Attackers can craft...
How severe is CVE-2019-25332?
CVE-2019-25332 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-25332?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.