Vulnerabilities
Vulnerable Software
Texas Imperial Software:  >> Wftpd  Security Vulnerabilities
Texas Imperial Software WFTPD and WFTPD Pro Server 3.25 and earlier allow remote attackers to cause a denial of service (application crash) via a long SITE ADMIN command.
CVSS Score
5.0
EPSS Score
0.034
Published
2007-01-18
Buffer overflow in Texas Imperial Software WFTPD Pro Server 3.23.1.1 allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) via crafted APPE commands that contain "/" (slash) or "\" (backslash) characters.
CVSS Score
5.8
EPSS Score
0.174
Published
2006-11-10
Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands.
CVSS Score
6.5
EPSS Score
0.811
Published
2006-08-24
The Control Panel applet in WFTPD and WFTPD Pro 3.21 R1 and R2 allows remote authenticated users to cause a denial of service (crash) via a long FTP command.
CVSS Score
5.0
EPSS Score
0.052
Published
2004-12-31
Stack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users to execute arbitrary code via long (1) LIST, (2) NLST, or (3) STAT commands.
CVSS Score
7.2
EPSS Score
0.001
Published
2004-11-23
WFTPD Pro Server 3.21 Release 1 allocates memory for a command until a 0Ah byte (newline) is sent, which allows local users to cause a denial of service (CPU consumption) by continuing to send a long command that does not contain a newline.
CVSS Score
2.1
EPSS Score
0.001
Published
2004-11-23
WFTPD Pro Server 3.21 allows remote authenticated users to cause a denial of service (crash) via a series of long MLIST commands.
CVSS Score
5.0
EPSS Score
0.06
Published
2004-08-29
Directory traversal vulnerability in WFTPD 3.00 R5 allows a remote attacker to view arbitrary files via a dot dot attack in the CD command.
CVSS Score
7.5
EPSS Score
0.03
Published
2001-09-20
WFTPD 3.00 R5 allows a remote attacker to cause a denial of service by making repeated requests to cd to the floppy drive (A:\).
CVSS Score
5.0
EPSS Score
0.008
Published
2001-09-20
Directory traversal vulnerability in Winsock FTPd (WFTPD) 3.00 and 2.41 with the "Restrict to home directory" option enabled allows local users to escape the home directory via a "/../" string, a variation of the .. (dot dot) attack.
CVSS Score
5.0
EPSS Score
0.002
Published
2001-01-09


Contact Us

Shodan ® - All rights reserved