CVE-2006-2027 EXPLOIT
6.5
MEDIUM · CVSS 2.0 · EPSS 3.9% (pctl 90)
Patch early
A public exploit exists.
Description
Buffer overflow in Unicode processing in the logging functionality in Pablo Software Solutions Quick 'n Easy FTP Server Professional and Lite, probably 3.0, allows remote authenticated users to execute arbitrary code by sending a command with a long argument, which triggers a buffer overflow when an admin selects the Logging section in the FTP server main window. NOTE: the original researcher claims that the vendor disputes this issue.
Scoring
| CVSS | 6.5 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
| EPSS | 3.89% — more likely to be exploited than 90% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-04-26 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| pablo software solutions | quick n easy ftp server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Quick 'n EasY 2.4 FTP Server - Remote Denial of Service | 2004-10-24 |
References
- http://securityreason.com/securityalert/788
- http://www.osvdb.org/25235
- http://www.securityfocus.com/archive/1/431920/100/0/threaded
- http://www.securityfocus.com/bid/17681
- http://securityreason.com/securityalert/788
- http://www.osvdb.org/25235
- http://www.securityfocus.com/archive/1/431920/100/0/threaded
- http://www.securityfocus.com/bid/17681
→ the Explorer · watch your stack · NVD