peter bassill · operator
$ cve CVE-2006-2027 JSON

CVE-2006-2027 EXPLOIT

6.5
MEDIUM · CVSS 2.0 · EPSS 3.9% (pctl 90)

Patch early

A public exploit exists.

Description

Buffer overflow in Unicode processing in the logging functionality in Pablo Software Solutions Quick 'n Easy FTP Server Professional and Lite, probably 3.0, allows remote authenticated users to execute arbitrary code by sending a command with a long argument, which triggers a buffer overflow when an admin selects the Logging section in the FTP server main window. NOTE: the original researcher claims that the vendor disputes this issue.

Scoring

CVSS6.5 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS3.89% — more likely to be exploited than 90% of all CVEs
On CISA KEVno
Public exploityes
Published2006-04-26
Last modified2026-06-16

Affected (1)

VendorProduct
pablo software solutionsquick n easy ftp server

Public exploits

SourceTitleDate
exploit-dbQuick 'n EasY 2.4 FTP Server - Remote Denial of Service2004-10-24

References

→ the Explorer  ·  watch your stack  ·  NVD