FTP Shell Server 6.83 contains a buffer overflow vulnerability in the 'Account name to ban' field that allows local attackers to execute arbitrary code by supplying a crafted string. Attackers can inject shellcode through the account name parameter in the Manage FTP Accounts dialog to overwrite the return address and execute calc.exe or other commands.
Metrics
Affected Vendors & Products
References
History
Mon, 23 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ftpshell
Ftpshell ftpshell Server |
|
| Vendors & Products |
Ftpshell
Ftpshell ftpshell Server |
Sun, 22 Mar 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FTP Shell Server 6.83 contains a buffer overflow vulnerability in the 'Account name to ban' field that allows local attackers to execute arbitrary code by supplying a crafted string. Attackers can inject shellcode through the account name parameter in the Manage FTP Accounts dialog to overwrite the return address and execute calc.exe or other commands. | |
| Title | FTP Shell Server 6.83 Buffer Overflow via Account Name | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-03-22T13:38:50.375Z
Updated: 2026-03-23T16:14:40.047Z
Reserved: 2026-03-22T13:34:07.967Z
Link: CVE-2019-25619
Updated: 2026-03-23T16:14:36.818Z
Status : Awaiting Analysis
Published: 2026-03-22T14:16:30.873
Modified: 2026-03-23T14:31:37.267
Link: CVE-2019-25619
No data.