WS_FTP Server contains a boundary error when handling user input to the FTP commands "APPE" and "STAT". Successful exploitation allows execution of arbitrary code with the privileges of the FTP server. A valid user account is required for exploitation.
Classification
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution
Currently there is no vendor patch that fixes this vulnerability. The vendor has stated that a patch will be released soon. Do not allow untrusted users access to the FTP server.