📦

wu-ftpd

Vendor: washington_university

Actively Exploited 0 CISA KEV List
PoC / Exploits 9 Code Available
Total RCEs 3 Remote Access
Total CVEs 31 Total Indexed
Avg. EPSS 11.43% Exploit Prob.
Latest CVE CVE-2005-0256 May 02

Security Vulnerability Index

Page 2 / 4
10.0 CVSS
CVE-2001-0187
RCE Exploit Found

Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands via a malformed argument that is recorded in a PASV port assignment.

EPSS: 8.92%
5.0 CVSS
CVE-2000-0574
Exploit Found

FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of service or execute arbitrary commands.

EPSS: 12.74%
7.5 CVSS
CVE-1999-0997
Exploit Found

wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.

EPSS: 3.82%
10.0 CVSS

Buffer overflow in WU-FTPD and related FTP servers allows remote attackers to gain root privileges via MAPPING_CHDIR.

EPSS: 1.35%
10.0 CVSS
CVE-1999-0368
Exploit Found

Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.

EPSS: 48.33%