CVE-2018-25226

FTPShell Server 6.83 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the account name field. Attackers can trigger a denial of service by pasting a 417-byte payload into the 'Account name to ban' parameter within the Manage FTP Accounts interface.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ftpshell:ftpshell_server:6.83:*:*:*:*:*:*:*

History

31 Mar 2026, 19:24

Type Values Removed Values Added
CPE cpe:2.3:a:ftpshell:ftpshell_server:6.83:*:*:*:*:*:*:*
References () http://www.ftpshell.com/downloadserver.htm - () http://www.ftpshell.com/downloadserver.htm - Broken Link
References () http://www.ftpshell.com/index.htm - () http://www.ftpshell.com/index.htm - Product
References () https://www.exploit-db.com/exploits/46430 - () https://www.exploit-db.com/exploits/46430 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/ftpshell-server-denial-of-service-via-account-name - () https://www.vulncheck.com/advisories/ftpshell-server-denial-of-service-via-account-name - Third Party Advisory
First Time Ftpshell
Ftpshell ftpshell Server
Summary
  • (es) FTPShell Server 6.83 contiene una vulnerabilidad de desbordamiento de búfer que permite a atacantes locales bloquear la aplicación al suministrar una cadena excesivamente larga en el campo de nombre de cuenta. Los atacantes pueden desencadenar una denegación de servicio al pegar una carga útil de 417 bytes en el parámetro 'Account name to ban' dentro de la interfaz de Gestión de Cuentas FTP.

30 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-30 12:16

Updated : 2026-03-31 19:24


NVD link : CVE-2018-25226

Mitre link : CVE-2018-25226

CVE.ORG link : CVE-2018-25226


JSON object : View

Products Affected

ftpshell

  • ftpshell_server
CWE
CWE-787

Out-of-bounds Write