CVE-2010-20107 describes a stack-based buffer overflow in FTP Synchronizer Professional versions up to 4.0.73.274. This vulnerability is triggered when the client connects to a malicious FTP server and issues a LIST command, where an overly long filename in the server's response corrupts the Structured Exception Handler (SEH). With a CVSS score of 8.5 (HIGH), this flaw allows for potential remote code execution with low attack complexity, requiring user interaction. While not actively exploited in the wild, a Metasploit module exists, and the vulnerability has garnered significant community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Liuxz Software | FTP Synchronizer Professional | >= 0, <= 4.0.73.274CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.