CVE-2011-5166 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 6.5% (pctl 94)
Patch early
A public exploit exists.
Description
Multiple stack-based buffer overflows in KnFTP 1.0.0 allow remote attackers to execute arbitrary code via a long string to the (1) USER, (2) PASS, (3) REIN, (4) QUIT, (5) PORT, (6) PASV, (7) TYPE, (8) STRU, (9) MODE, (10) RETR, (11) STOR, (12) APPE, (13) ALLO, (14) REST, (15) RNFR, (16) RNTO, (17) ABOR, (18) DELE, (19) CWD, (20) LIST, (21) NLST, (22) SITE, (23) STST, (24) HELP, (25) NOOP, (26) MKD, (27) RMD, (28) PWD, (29) CDUP, (30) STOU, (31) SNMT, (32) SYST, and (33) XPWD commands.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 6.48% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-09-15 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| elif keir | knftp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | KnFTP 1.0 - Remote Buffer Overflow (DEP Bypass) (Metasploit) | 2011-11-07 |
| exploit-db | KnFTP 1.0.0 Server - 'USER' Remote Buffer Overflow | 2011-09-19 |
| exploit-db | KnFTP 1.0.0 Server - Multiple Buffer Overflows (PoC) (SEH) | 2011-09-18 |
| exploit-db | KnFTP Server - Remote Buffer Overflow | 2011-09-12 |
References
- http://archives.neohapsis.com/archives/bugtraq/2011-09/0015.html
- http://secunia.com/advisories/45907
- http://www.exploit-db.com/exploits/17819
- http://www.exploit-db.com/exploits/17856
- http://www.exploit-db.com/exploits/17870
- http://www.exploit-db.com/exploits/18089
- http://www.osvdb.org/75147
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69557
- http://archives.neohapsis.com/archives/bugtraq/2011-09/0015.html
- http://secunia.com/advisories/45907
- http://www.exploit-db.com/exploits/17819
- http://www.exploit-db.com/exploits/17856
- http://www.exploit-db.com/exploits/17870
- http://www.exploit-db.com/exploits/18089
- http://www.osvdb.org/75147
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69557
→ the Explorer · watch your stack · NVD