An unspecified vulnerability in XLink Omni-NFS Enterprise allows remote attackers to execute arbitrary code via unknown vectors. The vulnerability was demonstrated by the exploit vd_xlink2.pm. The exact nature of the vulnerability, including the affected function or component, is not disclosed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (modules/exploits/windows/ftp/xlink_server.rb) that exploits a stack buffer overflow vulnerability in the Xlink FTP Server bundled with Omni-NFS Enterprise 5.2 (CVE-2006-5792). The exploit works by sending an overly long FTP request to the server, causing a buffer overflow and allowing arbitrary code execution. The module is written in Ruby and leverages the Metasploit framework's payload system, allowing the attacker to specify a custom payload (such as a reverse shell) up to 260 bytes, with certain bad characters filtered. The exploit targets the FTP service (typically on port 21/tcp) and is operational, requiring the attacker to connect to the vulnerable FTP server. The module includes a check method to detect the presence of the vulnerable service by examining the FTP banner. The only fingerprintable endpoints are the FTP service itself and a reference to the vendor's website. The code is structured as a standard Metasploit exploit module, with initialization, check, and exploit methods.
This repository contains a single Metasploit exploit module targeting a stack buffer overflow vulnerability in Xlink FTP Client 32 Version 3.01, which is bundled with Omni-NFS Enterprise 5.2. The exploit works by acting as a malicious FTP server (listening on TCP port 21) and sending an overly long response to a connecting client. If the vulnerable client connects, the crafted response triggers a buffer overflow, allowing arbitrary code execution with the attacker's chosen payload (up to 550 bytes, with certain bad characters filtered). The module supports two specific Windows targets (XP Pro SP3 English and 2000 SP4 English) and is fully integrated into the Metasploit framework, allowing for payload selection and automated exploitation. No external network endpoints or domains are hardcoded; the exploit is designed to be run by an attacker awaiting connections from vulnerable clients.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.