CVE-2018-25226

Severity CVSS v4.0:
MEDIUM
Type:
CWE-787 Out-of-bounds Write
Publication date:
30/03/2026
Last modified:
31/03/2026

Description

FTPShell Server 6.83 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the account name field. Attackers can trigger a denial of service by pasting a 417-byte payload into the 'Account name to ban' parameter within the Manage FTP Accounts interface.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ftpshell:ftpshell_server:6.83:*:*:*:*:*:*:*