Vulnerabilities > CVE-2004-2523 - Unspecified vulnerability in Openftpd FTP Server 0.29.4/0.30/0.30.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in the message argument.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
Exploit-Db
description OpenFTPD <= 0.30.1 (message system) Remote Shell Exploit. CVE-2004-2523. Remote exploit for linux platform id EDB-ID:373 last seen 2016-01-31 modified 2004-08-04 published 2004-08-04 reporter infamous41md source https://www.exploit-db.com/download/373/ title OpenFTPD <= 0.30.1 message system Remote Shell Exploit description OpenFTPD (<= 0.30.2) Remote Exploit. CVE-2004-2523. Remote exploit for linux platform id EDB-ID:372 last seen 2016-01-31 modified 2004-08-03 published 2004-08-03 reporter Andi source https://www.exploit-db.com/download/372/ title OpenFTPD <= 0.30.2 - Remote Exploit
Nessus
NASL family | FTP |
NASL id | OPENFTPD_DETECTION.NASL |
description | The remote host is running OpenFTPD - an FTP server designed to help file sharing (aka |
last seen | 2020-06-02 |
modified | 2004-08-01 |
plugin id | 14179 |
published | 2004-08-01 |
reporter | This script is Copyright (C) 2004-2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/14179 |
title | OpenFTPD SITE MSG FTP Command Format String |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2004-07/0350.html
- http://archives.neohapsis.com/archives/bugtraq/2004-07/0350.html
- http://archives.neohapsis.com/archives/bugtraq/2004-08/0017.html
- http://archives.neohapsis.com/archives/bugtraq/2004-08/0017.html
- http://secunia.com/advisories/12174
- http://secunia.com/advisories/12174
- http://securitytracker.com/id?1010823
- http://securitytracker.com/id?1010823
- http://www.openftpd.org:9673/openftpd
- http://www.openftpd.org:9673/openftpd
- http://www.osvdb.org/8261
- http://www.osvdb.org/8261
- http://www.securityfocus.com/bid/10830
- http://www.securityfocus.com/bid/10830
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16843
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16843