CVE-2008-3734
RCETitle: Ipswitch Ws Ftp Home RCE
RCE
Proof Of Concept
PoC Available for CVE-2008-3734
CWE Category
CWE-134
Published Date
Aug 20, 2008
Modified Date
Apr 09, 2025
Exploit Status
Available
Score
9.3
CVSS v2.0
Exploit Probability (EPSS)
69.43%
Vulnerability Summary
CVE-2008-3734: Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP servers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in a connection greeting (response).
Impacted Vendors
Reference Links
http://secunia.com/advisories/31504
http://securityreason.com/securityalert/4173
http://www.securityfocus.com/bid/30720
http://www.securitytracker.com/id?1020713
http://www.securitytracker.com/id?1020714
https://exchange.xforce.ibmcloud.com/vulnerabilities/44512
https://www.exploit-db.com/exploits/6257
http://secunia.com/advisories/31504
http://securityreason.com/securityalert/4173
http://www.securityfocus.com/bid/30720
http://www.securitytracker.com/id?1020713
http://www.securitytracker.com/id?1020714
https://exchange.xforce.ibmcloud.com/vulnerabilities/44512
https://www.exploit-db.com/exploits/6257
CVSS v2.0
Source Entity
[email protected]
Severity
HIGH
9.3
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:M/Au:N/C:C/I:C/A:C
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2008-3734 Exploits & PoCs (Proof Of Concept)
Exploit-DB
https://www.exploit-db.com/exploits/6257
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:M/Au:N/C:C/I:C/A:C
Affected Stack
No specific products linked.