7.5
CVSSv2

CVE-2005-0958

Published: 02/05/2005 Updated: 14/02/2024
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in the log_do function in log.c for YepYep mtftpd 0.0.3, when the statistics option is enabled, allows remote malicious users to execute arbitrary code via the CWD command.

Vulnerable Product Search on Vulmon Subscribe to Product

yepyep mtftpd 0.2

yepyep mtftpd 0.3

yepyep mtftpd 0.1a

Exploits

/* \ mtftpd <= 003 remote root exploit / by darkeagle \ / discovered by darkeagle - xx1004 \ / (c) unl0ck research team [unl0ckorg] \ / greetz: unl0ckerZ, rosielloZ, nosystemZ, etc \ / [darkeagle@localhost darkeagle]$ /0x666-ftpd -a 127001 -p beautifulgirlz -u darkeagle mtftpd <= 003 remote root exploit by darkeagle ...