CVE-2002-0336

Galacticomm Worldgroup <= 3.20 - Buffer Overflow via FTP LIST Command

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0336. PoCs published by Limpid Byte.

AI-analyzed exploit summary This exploit triggers a denial-of-service (DoS) in Galacticomm Worldgroup FTP Server by sending a malformed LIST command with excessive '*/../' sequences. The server crashes upon processing the command, requiring a restart.

Description

Buffer overflow in Galacticomm Worldgroup FTP server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a LIST command containing a large number of / (slash), * (wildcard), and .. characters.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Limpid Byte · cdoswindows
https://www.exploit-db.com/exploits/21305

This exploit triggers a denial-of-service (DoS) in Galacticomm Worldgroup FTP Server by sending a malformed LIST command with excessive '*/../' sequences. The server crashes upon processing the command, requiring a restart.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Galacticomm Worldgroup FTP Server 3.xx
Auth required
Prerequisites: network access to the FTP server · valid login credentials
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/8297.php
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4185
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=101484128203523&w=2

Scores

EPSS 0.0513
EPSS Percentile 91.3%

Details

Status published
Products (2)
galacticomm_technologies/worldgroup 3.20
galacticomm_technologies/worldgroup_lite_personal_server 3.20
Published Jun 25, 2002
Tracked Since Feb 18, 2026