CVE-2000-0038
glftpd < 1.17.2 - Default Root Account with Hardcoded Credentials
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2000-0038. PoCs published by suid.
AI-analyzed exploit summary This exploit leverages a command injection vulnerability in GlFtpd's ZIPCHK feature, allowing arbitrary command execution by manipulating filenames. It also describes default credentials and world-writeable directory issues.
Description
glFtpD includes a default glftpd user account with a default password and a UID of 0.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by suid · textremoteunix
https://www.exploit-db.com/exploits/19690
This exploit leverages a command injection vulnerability in GlFtpd's ZIPCHK feature, allowing arbitrary command execution by manipulating filenames. It also describes default credentials and world-writeable directory issues.
Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
GlFtpd (version not specified)
Auth required
Prerequisites:
ability to upload files to the FTP server · access to a local account or localhost connection
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (1)
Core 1
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-2000-0038
Scores
EPSS
0.0657
EPSS Percentile
93.0%
Details
Status
published
Products (1)
glftpd/glftpd
< 1.17.2
Published
Dec 23, 1999
Tracked Since
Feb 18, 2026