Vulnerability Name:

CVE-2004-1885 (CCN-15558)

Assigned:2004-03-23
Published:2004-03-23
Updated:2019-08-13
Summary:Ipswitch WS_FTP Server 4.0.2 allows remote authenticated users to execute arbitrary programs as SYSTEM by using the SITE command to modify certain iFtpSvc options that are handled by iftpmgr.exe.
CVSS v3 Severity:9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
6.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Privileges
References:Source: CCN
Type: Full-Disclosure Mailing List, Tue Mar 23 2004 - 01:11:58 CST
Open the WS_FTP Server backdoor to SYSTEM

Source: MITRE
Type: CNA
CVE-2004-1885

Source: BUGTRAQ
Type: UNKNOWN
20040323 Open the WS_FTP Server backdoor to SYSTEM

Source: CCN
Type: SA11206
WS_FTP Server Multiple Vulnerabilities

Source: SECUNIA
Type: Exploit, Patch
11206

Source: CCN
Type: OSVDB ID: 4539
WS_FTP Server SITE Arbitrary Remote Command Execution

Source: BID
Type: Exploit
9953

Source: CCN
Type: BID-9953
Ipswitch WS_FTP Multiple Vulnerabilities

Source: CCN
Type: WS_FTP Web site
WS_FTP Server with SSH - Overview

Source: XF
Type: UNKNOWN
wsftp-siteftp-privilege-escalation(15558)

Source: XF
Type: UNKNOWN
wftp-site-gain-priviliege(15558)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:progress:ipswitch_ws_ftp_server:4.0.2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:progress:ipswitch_ws_ftp_server:4.0.2:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    progress ipswitch ws ftp server 4.0.2
    ipswitch ws ftp server 4.0.2