9 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:S/C:C/I:C/A:C
7.6 High
AI Score
Confidence
Low
0.256 Low
EPSS
Percentile
96.7%
Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via a long unicode string to (1) TListbox or (2) TComboBox.
CPE | Name | Operator | Version |
---|---|---|---|
flashfxp:flashfxp | flashfxp | eq | 4.2 |
archives.neohapsis.com/archives/bugtraq/2012-03/0002.html
osvdb.org/79767
seclists.org/fulldisclosure/2012/Mar/7
www.exploit-db.com/exploits/18555
www.flashfxp.com/forum/news/15473-flashfxp-4-2-released.html#post81101
www.securityfocus.com/bid/52259
www.vulnerability-lab.com/get_content.php?id=462
exchange.xforce.ibmcloud.com/vulnerabilities/73626