CVE-2006-4847
medium · 6.5Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long (1) XCRC, (2) XSHA1, or (3) XMD5 commands.
6.5
CVSS
85.3%
EPSS (exploit prob.)
100th
EPSS percentile
2006-09-19
Published
AV:N/AC:L/Au:S/C:P/I:P/A:P
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| ipswitch | ws_ftp_server | 1.0.1eval |
| ipswitch | ws_ftp_server | 1.0.2eval |
| ipswitch | ws_ftp_server | 3.0_1 |
| ipswitch | ws_ftp_server | 4.01 |
| ipswitch | ws_ftp_server | 5.02 |
| ipswitch | ws_ftp_server | 5.03 |
| progress | ws_ftp_server | <= 5.05 |
| progress | ws_ftp_server | 1.0.1 |
| progress | ws_ftp_server | 1.0.1.e |
| progress | ws_ftp_server | 1.0.2 |
| progress | ws_ftp_server | 1.0.2.e |
| progress | ws_ftp_server | 1.0.3 |
| progress | ws_ftp_server | 1.0.4 |
| progress | ws_ftp_server | 1.0.5 |
| progress | ws_ftp_server | 2.0 |
| progress | ws_ftp_server | 2.0.1 |
| progress | ws_ftp_server | 2.0.2 |
| progress | ws_ftp_server | 2.0.3 |
| progress | ws_ftp_server | 2.0.4 |
| progress | ws_ftp_server | 3.0 |
| progress | ws_ftp_server | 3.1 |
| progress | ws_ftp_server | 3.1.1 |
| progress | ws_ftp_server | 3.1.2 |
| progress | ws_ftp_server | 3.1.3 |
| progress | ws_ftp_server | 3.4 |
| progress | ws_ftp_server | 4.0 |
| progress | ws_ftp_server | 4.0.2 |
Check a specific version with /api/v1/cve/match.
References
- http://ipswitch.com/support/ws_ftp-server/releases/wr505hf1.asp
- http://secunia.com/advisories/21932
- http://www.osvdb.org/28939
- http://www.securityfocus.com/bid/20076
- http://www.vupen.com/english/advisories/2006/3655
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28983
- http://ipswitch.com/support/ws_ftp-server/releases/wr505hf1.asp
- http://secunia.com/advisories/21932
- http://www.osvdb.org/28939
- http://www.securityfocus.com/bid/20076
- http://www.vupen.com/english/advisories/2006/3655
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28983
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2006-4847