CVE-2007-1567

War FTP Daemon < 1.65 - Stack-Based Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 5 public exploits for CVE-2007-1567. PoCs published by niXel, Umesh Wanve, Winny Thomas.

AI-analyzed exploit summary This exploit targets a stack-based buffer overflow in WAR-FTPD 1.65 via the USER command. It includes a bind shellcode to open a port (7777) on the target system, leveraging a JMP ESP address for reliable exploitation across various Windows versions.

Description

Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors, as demonstrated by warftp_165.tar by Immunity. NOTE: this might be the same issue as CVE-1999-0256, CVE-2000-0131, or CVE-2006-2171, but due to Immunity's lack of details, this cannot be certain.

Exploits (5)

exploitdb WORKING POC VERIFIED
by niXel · cremotewindows
https://www.exploit-db.com/exploits/3570

This exploit targets a stack-based buffer overflow in WAR-FTPD 1.65 via the USER command. It includes a bind shellcode to open a port (7777) on the target system, leveraging a JMP ESP address for reliable exploitation across various Windows versions.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WAR-FTPD 1.65
No auth needed
Prerequisites: Network access to the WAR-FTPD server · Target must be running WAR-FTPD 1.65
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Umesh Wanve · perlremotewindows
https://www.exploit-db.com/exploits/3482

This exploit targets a buffer overflow vulnerability in WarFTP 1.65 by overwriting the SEH handler to achieve remote code execution. It uses a NOP sled and shellcode to spawn a calculator as a proof-of-concept.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WarFTP 1.65
No auth needed
Prerequisites: Network access to the target FTP server on port 21
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Winny Thomas · pythonremotewindows
https://www.exploit-db.com/exploits/3474

This exploit targets a stack overflow vulnerability in WarFTP 1.65 by sending a long username (>480 bytes) via the USER FTP command. It includes a portbind shellcode to bind a shell on TCP port 4444 and connects to it using telnet.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WarFTP 1.65
No auth needed
Prerequisites: Network access to the target FTP server · WarFTP 1.65 running on Windows 2000 Server SP4
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by TheMalwareGuardian · poc
https://github.com/TheMalwareGuardian/CVE-2007-1567

This repository contains a functional exploit for CVE-2007-1567, a stack-based buffer overflow in War FTP Daemon 1.65. It includes multiple Python scripts demonstrating the exploitation process, from fuzzing to achieving remote code execution via the USER command.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: War FTP Daemon 1.65
No auth needed
Prerequisites: Windows XP environment · War FTP Daemon 1.65 installed · Network access to TCP port 21
devstral-2 · analyzed Mar 24, 2026 Full analysis →
nomisec WORKING POC
by war4uthor · poc
https://github.com/war4uthor/CVE-2007-1567

This repository contains a functional exploit for CVE-2007-1567, targeting a buffer overflow vulnerability in WarFTP. It includes a fuzzer and a full exploit with shellcode for remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WarFTP 1.65
No auth needed
Prerequisites: Network access to the target FTP server · WarFTP 1.65 running on the target
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/22944
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24494
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/0933

Scores

EPSS 0.5055
EPSS Percentile 98.8%

Details

Status published
Products (1)
war_ftp_daemon/war_ftp_daemon < 1.65
Published Mar 21, 2007
Tracked Since Feb 18, 2026