CVE-2006-4948

ProSysInfo TFTP Server TFTPDWIN <0.4.2 - Buffer Overflow

Title source: llm

Description

Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to execute arbitrary code or cause a denial of service via a long file name. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16346
exploitdb WORKING POC VERIFIED
by Jacopo Cervini · perlremotewindows
https://www.exploit-db.com/exploits/3132
exploitdb WORKING POC VERIFIED
by SkD · perlremotewindows
https://www.exploit-db.com/exploits/7452
metasploit WORKING POC GREAT
by aushack · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/tftp/tftpdwin_long_filename.rb

Scores

EPSS 0.7863
EPSS Percentile 99.0%

Classification

Status draft

Affected Products (1)

prosysinfo/tftp_server_tftpdwin < 0.4.2

Timeline

Published Sep 23, 2006
Tracked Since Feb 18, 2026