CVE-2012-10035

Turbo FTP Server versions 1.30.823 and 1.30.826 contain a buffer overflow vulnerability in the handling of the PORT command. By sending a specially crafted payload, an unauthenticated remote attacker can overwrite memory structures and execute arbitrary code with SYSTEM privileges.
CVSS

No CVSS.

Configurations

No configuration.

History

07 Aug 2025, 16:15

Type Values Removed Values Added
Summary
  • (es) Las versiones 1.30.823 y 1.30.826 de Turbo FTP Server contienen una vulnerabilidad de desbordamiento de búfer en la gestión del comando PORT. Al enviar una payload especialmente manipulada, un atacante remoto no autenticado puede sobrescribir estructuras de memoria y ejecutar código arbitrario con privilegios SYSTEM.
References () https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/ftp/turboftp_port.rb - () https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/ftp/turboftp_port.rb -
References () https://www.exploit-db.com/exploits/22161 - () https://www.exploit-db.com/exploits/22161 -

05 Aug 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-05 20:15

Updated : 2025-08-07 16:15


NVD link : CVE-2012-10035

Mitre link : CVE-2012-10035

CVE.ORG link : CVE-2012-10035


JSON object : View

Products Affected

No product.

CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')