CVE-2010-20108 is a stack-based buffer overflow in FTPPad version 1.2.0 and earlier. The flaw is in the client's FTP directory listing parser when processing server responses to the LIST command. If FTPPad connects to a malicious or attacker-controlled FTP server and receives a crafted directory listing containing an excessively long directory name and filename, the application does not properly validate input length before copying the data into a stack buffer. This can overwrite the saved EIP and redirect execution flow, enabling arbitrary code execution in the context of the FTPPad process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (modules/exploits/windows/ftp/ftppad_list_reply.rb) that exploits a stack buffer overflow vulnerability in the FTPPad 1.2.0 FTP client (CVE-2010-20108). The exploit works by acting as a malicious FTP server: when a vulnerable FTPPad client connects and issues a LIST command, the server responds with a specially crafted directory listing containing an overly long folder name. This triggers a buffer overflow in the client, allowing the attacker to overwrite the saved instruction pointer and execute arbitrary code. The exploit includes a payload space of up to 3000 bytes (with bad characters filtered) and targets specific versions of the shlwapi DLL on Windows XP SP3 Professional (English and German). The module is written in Ruby and leverages the Metasploit framework's FTP server mixin. No hardcoded IPs or URLs are present, as the exploit is server-side and targets connecting clients. The main entry point is the Ruby file itself, which is structured as a standard Metasploit exploit module.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.