Executive brief
SpotFTP, a tool used for recovering FTP passwords, contains a flaw that allows the application to be crashed. By entering an excessively long string of text into the registration name field, a user can trigger a memory error that shuts down the software. While this primarily affects the availability of the tool on a specific computer, it could be used to disrupt password recovery operations.
Technical details
A classic buffer overflow (CWE-120) exists in SpotFTP FTP Password Recovery version 3.0.0.0 within the registration name input field. The vulnerability is triggered when a user pastes a specially crafted payload (approximately 1,000 characters) into the 'Name' field of the registration dialog. This lack of input validation leads to a memory corruption that causes the application to crash (Denial of Service). Exploitation requires local access and user interaction to paste the malicious string into the application interface. A public Proof of Concept (PoC) is available.
Affected products
- Nsasoft (Nsauditor) SpotFTP FTP Password Recovery 3.0.0.0
Timeline
- 2020-01-06: disclosed: Initial exploit PoC published on Exploit-DB
- 2026-02-11: advisory: CVE published and NVD entry created