Title: ComSndFTP Server Remote Format String Overflow Vulnerability
Software : ComSndFTP FTP Server
Software Version : ComSndFTP 1.3.7 Beta
Vendor: http://ftp.comsnd.com/
Vulnerability Published : 2012-06-07
Vulnerability Update Time :
Status :
Impact : Medium(CVSS2 Base : 5.0, AV:N/AC:L/Au:N/C:N/I:N/A:P)
Bug Description :
ComSndFTP Server is a free ftp server for windows.
It is possible for remote attackers to use USER command with any format string that will lead to a Denial Of Service flaw for the FTP service.
Credits : This vulnerability was discovered by demonalex(at)163(dot)com
mail: demonalex(at)163(dot)com / [email protected]
Pentester/Independent Researcher
Dark2S Security Team/HongKong PolyU