Back to CVE List

CVE-2018-25254

CRITICAL SEVERITY

CVSS Score & Metrics

Base Score
9.8 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

NICO-FTP 3.0.1.19 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by sending crafted FTP commands. Attackers can connect to the FTP service and send oversized data in response handlers to overwrite SEH pointers and redirect execution to injected shellcode.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-787
Source
NVD
Vendor
nico-ftp
Product
NICO-FTP

External References

Discussion (0)

Add Comment

No comments yet. Be the first!