5.5

CVE-2004-0342

Exploit
WFTPD Pro Server 3.21 Release 1, with the XeroxDocutech option enabled, allows local users to cause a denial of service (crash) via a (1) MKD or (2) XMKD command that causes an absolute path of 260 characters to be used, which overwrites a cookie with a null character, possibly due to an off-by-one error.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wftpd Pro Server ProjectWftpd Pro Server Version3.21 Updater1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.353
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:N/A:P
CWE-193 Off-by-one Error

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

http://secunia.com/advisories/11001
Broken Link
http://www.securityfocus.com/bid/9767
Patch
Third Party Advisory
Vendor Advisory
Exploit
Broken Link
VDB Entry
http://marc.info/?l=bugtraq&m=107801142924976&w=2
Mailing List
http://www.osvdb.org/4116
Broken Link
https://exchange.xforce.ibmcloud.com/vulnerabilities/15342
Third Party Advisory
VDB Entry