CVE-2006-5826

WFTPD Pro Server 3.23.1.1 - Authenticated Buffer Overflow via APPE Command

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-5826. PoCs published by Joxean Koret.

AI-analyzed exploit summary This exploit targets a buffer overflow in WFTPD Pro Server 3.23.1.1 via the APPE command, causing a denial-of-service (DoS). The PoC includes shellcode but is noted as only achieving DoS in its current form.

Description

Buffer overflow in Texas Imperial Software WFTPD Pro Server 3.23.1.1 allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) via crafted APPE commands that contain "/" (slash) or "\" (backslash) characters.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Joxean Koret · pythondoswindows
https://www.exploit-db.com/exploits/2734

This exploit targets a buffer overflow in WFTPD Pro Server 3.23.1.1 via the APPE command, causing a denial-of-service (DoS). The PoC includes shellcode but is noted as only achieving DoS in its current form.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: WFTPD Pro Server 3.23.1.1
No auth needed
Prerequisites: Network access to the FTP server · FTP service running on target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/20942
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1837
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017173
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/2734
Mailing List mailing-list x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=116295408114746&w=2
Mailing List mailing-list x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=116289234522958&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30079
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/450851/100/0/threaded

Scores

EPSS 0.1043
EPSS Percentile 95.2%

Details

Status published
Products (1)
texas_imperial_software/wftpd 3.23.1.1
Published Nov 10, 2006
Tracked Since Feb 18, 2026