CVE-2006-5789

WarFTPd 1.82.00-RC11 - Authenticated Denial of Service via Format String in FTP Commands

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-5789. PoCs published by Joxean Koret.

AI-analyzed exploit summary This exploit targets a denial-of-service vulnerability in WAR-FTPD by sending an overly long string to the CWD command, causing the server to crash. The PoC connects anonymously and verifies the exploit by attempting to reconnect.

Description

War FTP Daemon (WarFTPd) 1.82.00-RC11 allows remote authenticated users to cause a denial of service via a large number of "%s" format strings in (1) CWD, (2) CDUP, (3) DELE, (4) NLST, (5) LIST, (6) SIZE, and possibly other commands. NOTE: it is possible that vector 1 is an off-by-one variant or incomplete fix of CVE-2005-0312.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Joxean Koret · pythondoswindows
https://www.exploit-db.com/exploits/2735

This exploit targets a denial-of-service vulnerability in WAR-FTPD by sending an overly long string to the CWD command, causing the server to crash. The PoC connects anonymously and verifies the exploit by attempting to reconnect.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: WAR-FTPD (version not specified)
No auth needed
Prerequisites: Network access to the FTP server · FTP service running on target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4398
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1832
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017174
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20944
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30077
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/450804/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/22755

Scores

EPSS 0.0290
EPSS Percentile 85.1%

Details

CWE
CWE-399
Status published
Products (1)
jgaa/warftpd 1.82.00_rc11
Published Nov 07, 2006
Tracked Since Feb 18, 2026