20041122 WeOnlyDo! COM Ftp DELUXE ActiveX Control Buffer Overflow Vulnerabilitymailing list
http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029243.html CVE-2004-1118
wodFtpDLX Client - ActiveX Control Buffer Overflow Crash
Record summary
CVE-2004-1118 has a selected CVSS score of 10.0; EIP currently links 2 catalogued exploits.
Description
Buffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.0.0.10, and possibly other applications, allows remote attackers to execute arbitrary code via a long filename.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBwodFtpDLX Client - ActiveX Control Buffer Overflow CrashExploitDB exploitby KomradeNot analyzed1 file
ExploitDBCoffeeCup FTP Clients (Direct 6.2.0.62) (Free 3.0.0.10) - Remote Buffer OverflowExploitDB exploitby KomradeNot analyzed1 file
References
620041122 CoffeeCup FTP Clients Buffer Overflow Vulnerabilitymailing list
http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029244.html 20041122 WeOnlyDo! COM Ftp DELUXE ActiveX Control Buffer Overflow Vulnerabilitymailing list
http://marc.info/?l=bugtraq&m=110114233323417&w=2 11721vdb entry
http://www.securityfocus.com/bid/11721 wodftpdlx-long-filename-bo(18190)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/18190 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-1118