CVE-2004-1439

BlackJumboDog 3.x - Remote Code Execution via Long FTP Commands

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2004-1439. PoCs published by Delikon, Tal Zeltzer.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in BlackJumboDog FTP Server version 3.6.1. It sends a crafted USER command with a long buffer containing a return address and shellcode to achieve remote code execution, then uploads and executes an arbitrary file via a secondary connection on port 7777.

Description

Buffer overflow in BlackJumboDog 3.x allows remote attackers to execute arbitrary code via long FTP commands such as (1) USER, (2) PASS, (3) RETR,(4) CWD, (5) XMKD, and (6) XRMD.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Delikon · cremotewindows
https://www.exploit-db.com/exploits/439

This exploit targets a buffer overflow vulnerability in BlackJumboDog FTP Server version 3.6.1. It sends a crafted USER command with a long buffer containing a return address and shellcode to achieve remote code execution, then uploads and executes an arbitrary file via a secondary connection on port 7777.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: BlackJumboDog FTP Server 3.6.1
No auth needed
Prerequisites: Network access to the target FTP server · Target running BlackJumboDog FTP Server 3.6.1 on Windows
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Tal Zeltzer · perlremotewindows
https://www.exploit-db.com/exploits/378

This exploit targets a buffer overflow vulnerability in the BlackJumboDog FTP server via a maliciously crafted PASS command. It delivers a Metasploit-generated win32_bind shellcode to achieve remote code execution on Windows 2000 SP4.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: BlackJumboDog FTP Server
No auth needed
Prerequisites: Network access to the target FTP server · Target running Windows 2000 SP4 with BlackJumboDog FTP Server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16842
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/12203
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/714584
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10834

Scores

EPSS 0.1585
EPSS Percentile 96.5%

Details

Status published
Products (1)
sapporoworks/black_jumbodog 3.6.1
Published Dec 31, 2004
Tracked Since Feb 18, 2026