20040108 Windows FTP Server Format String Vulnerabilitymailing list
http://marc.info/?l=bugtraq&m=107367110805273&w=2 CVE-2004-0069
HD Soft Windows FTP Server 1.5/1.6 - 'Username' Format String
Record summary
CVE-2004-0069 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBHD Soft Windows FTP Server 1.5/1.6 - 'Username' Format StringExploitDB exploitby mandragoreNot analyzed1 file
References
520040113 exploit for HD Soft Windows FTP Server 1.6mailing list
http://marc.info/?l=bugtraq&m=107401398014761&w=2 9385vdb entry
http://www.securityfocus.com/bid/9385 1008658vdb entry
http://www.securitytracker.com/id?1008658 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-0069