Vulnerabilities > CVE-2006-4318 - Buffer Overflow vulnerability in Texas Imperial Software Wftpd 3.23

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
texas-imperial-software
exploit available
metasploit

Summary

Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands.

Vulnerable Configurations

Part Description Count
Application
Texas_Imperial_Software
1

Exploit-Db

  • descriptionWFTPD 3.23 (SIZE) Remote Buffer Overflow Exploit. CVE-2006-4318. Remote exploit for windows platform
    fileexploits/windows/remote/2233.c
    idEDB-ID:2233
    last seen2016-01-31
    modified2006-08-21
    platformwindows
    port21
    published2006-08-21
    reporterh07
    sourcehttps://www.exploit-db.com/download/2233/
    titleWFTPD 3.23 SIZE Remote Buffer Overflow Exploit
    typeremote
  • descriptionTexas Imperial Software WFTPD 3.23 SIZE Overflow. CVE-2006-4318. Remote exploit for windows platform
    idEDB-ID:16741
    last seen2016-02-02
    modified2010-06-22
    published2010-06-22
    reportermetasploit
    sourcehttps://www.exploit-db.com/download/16741/
    titleTexas Imperial Software WFTPD 3.23 SIZE Overflow

Metasploit

descriptionThis module exploits a buffer overflow in the SIZE verb in Texas Imperial's Software WFTPD 3.23.
idMSF:EXPLOIT/WINDOWS/FTP/WFTPD_SIZE
last seen2020-03-11
modified2017-07-24
published2007-03-26
referenceshttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4318
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/ftp/wftpd_size.rb
titleTexas Imperial Software WFTPD 3.23 SIZE Overflow

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/83181/wftpd_size.rb.txt
idPACKETSTORM:83181
last seen2016-12-05
published2009-11-26
reporterMC
sourcehttps://packetstormsecurity.com/files/83181/Texas-Imperial-Software-WFTPD-3.23-SIZE-Overflow.html
titleTexas Imperial Software WFTPD 3.23 SIZE Overflow

Statements

contributorTexas Imperial Software
lastmodified2011-01-07
organizationTexas Imperial Software
statementTexas Imperial Software has tested this issue against current versions of WFTPD and WFTPD Pro, and finds that versions after 3.23 are not vulnerable. Users of WFTPD or WFTPD Pro should update to the most current version in order to address this issue. The update is free to fully registered users unregistered users can download a fresh copy of the shareware version of the application.