Vulnerabilities > CVE-2006-3952 - Remote Buffer Overflow vulnerability in EFS Software EFS FTP Server 2.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Stack-based buffer overflow in EFS Software Easy File Sharing FTP Server 2.0 allows remote attackers to execute arbitrary code via a long argument to the PASS command. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description Easy File Sharing FTP Server 2.0 (PASS) Remote Exploit (Win2K SP4). CVE-2006-3952. Remote exploit for windows platform id EDB-ID:3579 last seen 2016-01-31 modified 2007-03-26 published 2007-03-26 reporter Winny Thomas source https://www.exploit-db.com/download/3579/ title Easy File Sharing FTP Server 2.0 PASS Remote Exploit Win2K SP4 description Easy File Sharing FTP Server 3.5 - Stack Buffer Overflow. CVE-2006-3952. Remote exploit for windows platform id EDB-ID:33538 last seen 2016-02-03 modified 2014-05-27 published 2014-05-27 reporter superkojiman source https://www.exploit-db.com/download/33538/ title Easy File Sharing FTP Server 3.5 - Stack Buffer Overflow description Easy File Sharing FTP Server 2.0 (PASS) Remote Exploit (PoC). CVE-2006-3952. Remote exploit for windows platform id EDB-ID:2234 last seen 2016-01-31 modified 2006-08-21 published 2006-08-21 reporter h07 source https://www.exploit-db.com/download/2234/ title Easy File Sharing FTP Server 2.0 PASS Remote Exploit PoC description Easy File Sharing FTP Server 2.0 PASS Overflow. CVE-2006-3952. Remote exploit for windows platform id EDB-ID:16742 last seen 2016-02-02 modified 2010-05-09 published 2010-05-09 reporter metasploit source https://www.exploit-db.com/download/16742/ title Easy File Sharing FTP Server 2.0 PASS Overflow
Metasploit
description | This module exploits a stack buffer overflow in the Easy File Sharing 2.0 service. By sending an overly long password, an attacker can execute arbitrary code. |
id | MSF:EXPLOIT/WINDOWS/FTP/EASYFILESHARING_PASS |
last seen | 2020-01-25 |
modified | 2017-07-24 |
published | 2007-03-26 |
references | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3952 |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/ftp/easyfilesharing_pass.rb |
title | Easy File Sharing FTP Server 2.0 PASS Overflow |
Nessus
NASL family | FTP |
NASL id | EFS_FTP_SERVER_PASS_OVERFLOW.NASL |
description | The remote host appears to be using Easy File Sharing FTP Server, an FTP server for Windows. The version of Easy File Sharing FTP Server installed on the remote host contains a stack-based buffer overflow vulnerability that can be exploited by an unauthenticated attacker with a specially crafted PASS command to crash the affected application or execute arbitrary code on the affected host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 24021 |
published | 2007-01-17 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/24021 |
title | Easy File Sharing FTP Server PASS Command Overflow |
code |
|
Packetstorm
data source https://packetstormsecurity.com/files/download/83010/easyfilesharing_pass.rb.txt id PACKETSTORM:83010 last seen 2016-12-05 published 2009-11-26 reporter MC source https://packetstormsecurity.com/files/83010/Easy-File-Sharing-FTP-Server-2.0-PASS-Overflow.html title Easy File Sharing FTP Server 2.0 PASS Overflow data source https://packetstormsecurity.com/files/download/126845/easysharingftp-overflow.txt id PACKETSTORM:126845 last seen 2016-12-05 published 2014-05-30 reporter superkojiman source https://packetstormsecurity.com/files/126845/Easy-File-Sharing-FTP-Server-3.5-Buffer-Overflow.html title Easy File Sharing FTP Server 3.5 Buffer Overflow
Seebug
bulletinFamily | exploit |
description | No description provided by source. |
id | SSV:86747 |
last seen | 2017-11-19 |
modified | 2014-07-01 |
published | 2014-07-01 |
reporter | Root |
source | https://www.seebug.org/vuldb/ssvid-86747 |
title | Easy File Sharing FTP Server 3.5 - Stack Buffer Overflow |