InstantServers MiniPortal FTP Login Remote Buffer Overlow Vulnerability
BID:4073
Info
InstantServers MiniPortal FTP Login Remote Buffer Overlow Vulnerability
| Bugtraq ID: | 4073 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0260 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 09 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | Discovered by Strumpf Noir Society <[email protected]>. |
| Vulnerable: |
InstantServers MiniPortal 1.1.5 |
| Not Vulnerable: |
InstantServers MiniPortal 1.1.6 |
Discussion
InstantServers MiniPortal FTP Login Remote Buffer Overlow Vulnerability
InstantServers MiniPortal is a web server package for Windows based machines, based on the Apache project web server. It includes a web based administrative interface, and a bundled FTP server.
A vulnerability has been reported in the MiniPortal FTP server. It is possible to overflow a buffer when logging into the FTP server. This allows an arbitrary remote user able to connect to the FTP server to execute arbitrary code. The FTP server is installed by default.
InstantServers MiniPortal is a web server package for Windows based machines, based on the Apache project web server. It includes a web based administrative interface, and a bundled FTP server.
A vulnerability has been reported in the MiniPortal FTP server. It is possible to overflow a buffer when logging into the FTP server. This allows an arbitrary remote user able to connect to the FTP server to execute arbitrary code. The FTP server is installed by default.
Exploit / POC
InstantServers MiniPortal FTP Login Remote Buffer Overlow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.