FileWrangler <= 5.30 suffers from a stack-based buffer overflow vulnerability when parsing directory listings from an FTP server. A malicious server can send an overlong folder name in response to a LIST command, triggering memory corruption during client-side rendering. Exploitation requires passive user interaction—simply connecting to the server—without further input. Successful exploitation may lead to arbitrary code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module that exploits a stack buffer overflow vulnerability in the FileWrangler 5.30 FTP client for Windows (CVE-2010-20045). The exploit works by running a malicious FTP server that, when a vulnerable FileWrangler client connects and issues a directory listing (LIST command), sends a specially crafted directory name that overflows a buffer in the client. The module uses an egghunter technique to locate and execute the payload, which can be any Metasploit-compatible shellcode (up to 3000 bytes, with certain bad characters filtered out). The exploit is operational and allows for arbitrary code execution on the victim's machine. The only file in the repository is the Metasploit module itself, written in Ruby, and it leverages Metasploit's FTP server and egghunter mixins. The main attack vector is network-based, requiring the victim to connect to the attacker's FTP server. The only fingerprintable endpoint is the reference to 'wrangler.exe', the target binary on the victim system.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.