CVE-2006-4318 describes a critical buffer overflow vulnerability in WFTPD Server version 3.23, allowing remote attackers to execute arbitrary code. This flaw is triggered by sending an overly long SIZE command to the server. With a CVSS score of 6.5, it has a high attack vector and low complexity, potentially leading to partial compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, exploit modules are readily available in Metasploit and ExploitDB, indicating a high potential for exploitation, despite a lack of recent community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.23CPE matchmatch criteria | cpe:2.3:a:texas_imperial_software:wftpd:3.23:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.