CVE-2019-25619

Severity CVSS v4.0:
HIGH
Type:
CWE-787 Out-of-bounds Write
Publication date:
22/03/2026
Last modified:
22/03/2026

Description

FTP Shell Server 6.83 contains a buffer overflow vulnerability in the 'Account name to ban' field that allows local attackers to execute arbitrary code by supplying a crafted string. Attackers can inject shellcode through the account name parameter in the Manage FTP Accounts dialog to overwrite the return address and execute calc.exe or other commands.