CVE-2004-1118

WodFtpDLX ActiveX Component < 2.3.2.97 - Buffer Overflow via Long Filename

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2004-1118. PoCs published by Komrade.

AI-analyzed exploit summary This exploit creates a fake FTP server to trigger a buffer overflow in CoffeeCup FTP clients, spawning a reverse shell on port 5555. It supports both local and remote execution, targeting specific versions of CoffeeCup Direct FTP and Free FTP.

Description

Buffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.0.0.10, and possibly other applications, allows remote attackers to execute arbitrary code via a long filename.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Komrade · cremotewindows
https://www.exploit-db.com/exploits/650

This exploit creates a fake FTP server to trigger a buffer overflow in CoffeeCup FTP clients, spawning a reverse shell on port 5555. It supports both local and remote execution, targeting specific versions of CoffeeCup Direct FTP and Free FTP.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: CoffeeCup Direct FTP 6.2.0.62, CoffeeCup Free FTP 3.0.0.10
No auth needed
Prerequisites: Network access to target · Target must connect to the fake FTP server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Komrade · cdoswindows
https://www.exploit-db.com/exploits/649

This exploit creates a fake FTP server to trigger a buffer overflow in the WodFtpDLX ActiveX Control, causing a crash by overwriting the SEH handler with 0xDEADCODE. It supports both local and remote execution.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: WodFtpDLX.ocx versions 2.3.2.90, 2.3.0.0, 2.2.0.1
No auth needed
Prerequisites: Network access to target · Target application using WodFtpDLX ActiveX Control
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18190
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11721
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110114233323417&w=2

Scores

EPSS 0.0818
EPSS Percentile 94.1%

Details

Status published
Products (2)
weonlydo/wodftpdlx_activex_component
weonlydo/wodftpdlx_activex_component 2.1.1_8
Published Jan 10, 2005
Tracked Since Feb 18, 2026