Vulnerabilities > CVE-2005-2373 - Local Security vulnerability in Slimftpd 3.15/3.16
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Buffer overflow in SlimFTPd 3.15 and 3.16 allows remote authenticated users to execute arbitrary code via a long directory name to (1) LIST, (2) DELE or (3) RNFR commands.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description | SlimFTPd LIST Concatenation Overflow. CVE-2005-2373. Remote exploit for windows platform |
id | EDB-ID:16729 |
last seen | 2016-02-02 |
modified | 2010-10-05 |
published | 2010-10-05 |
reporter | metasploit |
source | https://www.exploit-db.com/download/16729/ |
title | SlimFTPd LIST Concatenation Overflow |
Metasploit
description | This module exploits a stack buffer overflow in the SlimFTPd server. The flaw is triggered when a LIST command is received with an overly-long argument. This vulnerability affects all versions of SlimFTPd prior to 3.16 and was discovered by Raphael Rigo. |
id | MSF:EXPLOIT/WINDOWS/FTP/SLIMFTPD_LIST_CONCAT |
last seen | 2020-01-14 |
modified | 2017-07-24 |
published | 2005-11-26 |
references | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2373 |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/ftp/slimftpd_list_concat.rb |
title | SlimFTPd LIST Concatenation Overflow |
Nessus
NASL family | FTP |
NASL id | SLIMFTPD_OVERFLOW.NASL |
description | The remote host appears to be using SlimFTPd, a free, small, standards-compliant FTP server for Windows. According to its banner, the version of SlimFTPd installed on the remote host is prone to one or more buffer overflow attacks that can lead to arbitrary code execution. Note that successful exploitation of either of these flaws requires an attacker first authenticate. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15704 |
published | 2004-11-13 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15704 |
title | SlimFTPd Multiple Command Handling Overflow |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/82997/slimftpd_list_concat.rb.txt |
id | PACKETSTORM:82997 |
last seen | 2016-12-05 |
published | 2009-11-26 |
reporter | riaf |
source | https://packetstormsecurity.com/files/82997/SlimFTPd-LIST-Concatenation-Overflow.html |
title | SlimFTPd LIST Concatenation Overflow |