Medium severity6.2NVD Advisory· Published Mar 30, 2026· Updated Mar 31, 2026
CVE-2018-25226
CVE-2018-25226
Description
FTPShell Server 6.83 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an excessively long string in the account name field. Attackers can trigger a denial of service by pasting a 417-byte payload into the 'Account name to ban' parameter within the Manage FTP Accounts interface.
Affected products
1- cpe:2.3:a:ftpshell:ftpshell_server:6.83:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.exploit-db.com/exploits/46430nvdExploitVDB Entry
- www.vulncheck.com/advisories/ftpshell-server-denial-of-service-via-account-namenvdThird Party Advisory
- www.ftpshell.com/downloadserver.htmnvdBroken Link
- www.ftpshell.com/index.htmnvdProduct
News mentions
0No linked articles in our index yet.