Vulnerabilities > CVE-2005-1873 - Remote Security vulnerability in Crob FTP 3.6.1

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
crob
nessus
exploit available

Summary

Multiple buffer overflows in Crob FTP 3.6.1, and possibly earlier versions, allow remote attackers to execute arbitrary code via (1) an FTP command with a large string followed by the RMD command with a long string or (2) a globbing ("*") character followed by a long string.

Vulnerable Configurations

Part Description Count
Application
Crob
1

Exploit-Db

descriptionCrob FTP Server <= 3.6.1 Remote Stack Overflow Exploit. CVE-2005-1873. Remote exploit for windows platform
idEDB-ID:1028
last seen2016-01-31
modified2005-06-03
published2005-06-03
reporterLeon Juranic
sourcehttps://www.exploit-db.com/download/1028/
titleCrob FTP Server <= 3.6.1 - Remote Stack Overflow Exploit

Nessus

NASL familyFTP
NASL idCROBFTP_OVERFLOWS.NASL
descriptionThe version of Crob FTP Server on the remote host suffers from multiple remote buffer overflows. Once authenticated, an attacker can exploit these vulnerabilities to crash the affected daemon and even execute arbitrary code remotely within the context of the affected service.
last seen2020-06-01
modified2020-06-02
plugin id19236
published2005-07-20
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/19236
titleCrob FTP Server < 3.6.1 build 263 Multiple Vulnerabilities