Sploitus

CVE-2001-0187

1 known exploit for CVE-2001-0187

Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers to execute arbitrary commands via a malformed argument that is recorded in a PASV port assignment.

Affected products
Wu-Ftpd
Washington University Wu-ftpd
= 2.4.1, 2.4.2_beta9, 2.4.2_beta18, 2.4.2_beta18_vr4, 2.4.2_beta18_vr5, 2.4.2_beta18_vr6, 2.4.2_beta18_vr7, 2.4.2_beta18_vr8, 2.4.2_beta18_vr9, 2.4.2_beta18_vr10, 2.4.2_beta18_vr11, 2.4.2_beta18_vr12, 2.4.2_beta18_vr13, 2.4.2_beta18_vr14, 2.4.2_beta18_vr15, 2.4.2_vr16, 2.4.2_vr17, 2.5, 2.6
Fix
Available
CVSS 2.0
10.0 HIGH
EPSS
5.7% (92th percentile)
NVD status
Modified
Published
2001-05-07
CVE-2001-0187 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2001-0187

Proof-of-concept code and exploit modules indexed by Sploitus