Vulnerability Name: | CVE-2006-5000 (CCN-41829) | ||||||||
Assigned: | 2006-09-26 | ||||||||
Published: | 2006-09-26 | ||||||||
Updated: | 2019-08-13 | ||||||||
Summary: | Multiple buffer overflows in WS_FTP Server 5.05 before Hotfix 1, and possibly other versions down to 5.0, have unknown impact and remote authenticated attack vectors via the (1) XCRC, (2) XMD5, and (3) XSHA1 commands. Note: in the early publication of this identifier on 20060926, the description was used for the wrong issue. | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P) 4.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
6.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-5000 Source: CCN Type: SECTRACK ID: 1016935 WS_FTP Buffer Overflow in XCRC, XSHA1, and XMD5 Commands Lets Remote Authenticated Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1016935 Source: CCN Type: Ipswitch Web site WS_FTP Server 5.05 Hotfix 1 Source: CONFIRM Type: Patch http://www.ipswitch.com/support/ws_ftp-server/releases/wr505hf1.asp Source: CCN Type: OSVDB ID: 30974 WS_FTP Server Multiple Command Overflow Source: BUGTRAQ Type: UNKNOWN 20060926 ZDI-06-029: Ipswitch WS_FTP Server Checksum Command Parsing Buffer Overflow Vulnerabilities Source: MISC Type: Vendor Advisory http://www.zerodayinitiative.com/advisories/ZDI-06-029.html Source: XF Type: UNKNOWN wsftp-multiple-commands-bo(41829) Source: XF Type: UNKNOWN wsftp-multiple-commands-bo(41829) Source: CCN Type: ZDI-06-029 Ipswitch WS_FTP Server Checksum Command Parsing Buffer Overflow Vulnerabilities | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |