PCMan's FTP Server 2.0.7 contains a buffer overflow in its handling of the FTP USER command. A remotely supplied overlong USER argument can overflow a buffer and enable execution of arbitrary code.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (10 hidden).
This repository contains a single Metasploit module (modules/exploits/windows/ftp/pcman_put.rb) that exploits a buffer overflow vulnerability in the PUT command of PCMAN FTP Server v2.0.7 (CVE-2013-4730). The exploit targets Windows XP SP3 English and requires authentication, though anonymous login is enabled by default. The module connects to the FTP service, authenticates, and sends a specially crafted PUT command to trigger the overflow and execute arbitrary code. The payload is customizable via Metasploit, with a default space of 1000 bytes and avoidance of null, newline, and carriage return characters. The exploit leverages a return address in msvcrt.dll to redirect execution. The repository is structured as a standard Metasploit exploit module and is operational, providing remote code execution on vulnerable targets.
This repository contains a single Metasploit module (modules/exploits/windows/ftp/pcman_stor.rb) that exploits a stack buffer overflow vulnerability (CVE-2013-4730) in the STOR command of PCMAN FTP Server v2.07 on Windows XP SP3 English. The exploit requires valid FTP credentials (post-authentication) and targets the FTP service over the network (typically port 21). The module constructs a malicious STOR command with a specially crafted payload that overflows the stack and overwrites the return address with a pointer to a 'push esp; ret' instruction in msvcrt.dll, allowing arbitrary code execution. The payload is customizable and avoids specific bad characters. The repository is structured as a standard Metasploit exploit module written in Ruby, and is operational, allowing attackers to gain code execution on vulnerable systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.