VendorsWashington Universitywu-ftpd2.4
Vulnerabilities

Washington University Wu-ftpd 2.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-1999-0080
Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the "site exec" command.
Published 1999-09-29 · Modified
10.0EPSS 0.040
CVE-1999-0017
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
Published 1999-09-29 · Modified
7.5EPSS 0.020
CVE-2001-0935
Vulnerability in wu-ftpd 2.6.0, and possibly earlier versions, which is unrelated to the ftpglob bug described in CVE-2001-0550.
Published 2002-02-02 · Modified
7.5EPSS 0.015
CVE-1999-1326
wu-ftpd 2.4 FTP server does not properly drop privileges when an ABOR (abort file transfer) command is executed during a file transfer, which causes a signal to be handled incorrectly and allows local and possibly remote attackers to read arbitrary files.
Published 2002-03-09 · Modified
5.0EPSS 0.015