CVE-1999-0080

wu-ftpd 2.4 - Authenticated Privilege Escalation via Site Exec Command

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-1999-0080. PoCs published by HORKimhab.

AI-analyzed exploit summary The repository contains a markdown file describing CVE-1999-0080, a vulnerability in wu-ftp FTP server 2.4 where misconfigured _PATH_EXECPATH settings allow remote authenticated users to gain root access via 'site exec'. However, no functional exploit code or technical details beyond a high-level description are provided.

Description

Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the "site exec" command.

Exploits (1)

github STUB
by HORKimhab · shellpoc
https://github.com/HORKimhab/poc-cve-collection/tree/main/1999/0xxx/CVE-1999-0080.md

The repository contains a markdown file describing CVE-1999-0080, a vulnerability in wu-ftp FTP server 2.4 where misconfigured _PATH_EXECPATH settings allow remote authenticated users to gain root access via 'site exec'. However, no functional exploit code or technical details beyond a high-level description are provided.

Classification
Stub 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Theoretical
Target: wu-ftp FTP server 2.4
Auth required
Prerequisites: Authenticated access to the FTP server · Misconfigured _PATH_EXECPATH setting (e.g., pointing to /bin)
mistral-large-3 · analyzed Jul 14, 2026 Full analysis →

References (1)

Core 1

Scores

EPSS 0.0390
EPSS Percentile 89.2%

Details

Status published
Products (1)
washington_university/wu-ftpd 2.4
Published Nov 30, 1995
Tracked Since Feb 18, 2026