Description
WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of "%s" sequences, possibly indicating a format string vulnerability.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by MC.Iglo · perldoswindows
https://www.exploit-db.com/exploits/25063
References (4)
Scores
EPSS
0.0133
EPSS Percentile
80.0%
Details
Status
published
Products (2)
war_ftp_daemon/war_ftp_daemon
1.8
war_ftp_daemon/war_ftp_daemon
1.82_rc9
Published
Jan 27, 2005
Tracked Since
Feb 18, 2026