CVE-2006-4847 describes multiple buffer overflow vulnerabilities in Ipswitch WS_FTP Server 5.05 prior to Hotfix 1, affecting both Ipswitch and Progress versions of the software. Authenticated attackers can exploit these flaws by sending overly long XCRC, XSHA1, or XMD5 commands, leading to arbitrary code execution. With a CVSS score of 6.5, this vulnerability is of medium severity, requiring network access and authentication for exploitation, but potentially allowing for complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, exploit modules are readily available in Metasploit and ExploitDB, indicating a high potential for exploitation, despite a lack of public community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.1evalCPE matchmatch criteria | cpe:2.3:a:ipswitch:ws_ftp_server:1.0.1eval:*:*:*:*:*:*:* | ||
1.0.2evalCPE matchmatch criteria | cpe:2.3:a:ipswitch:ws_ftp_server:1.0.2eval:*:*:*:*:*:*:* | ||
3.0_1CPE matchmatch criteria | cpe:2.3:a:ipswitch:ws_ftp_server:3.0_1:*:*:*:*:*:*:* | ||
4.01CPE matchmatch criteria | cpe:2.3:a:ipswitch:ws_ftp_server:4.01:*:*:*:*:*:*:* | ||
5.02CPE matchmatch criteria | cpe:2.3:a:ipswitch:ws_ftp_server:5.02:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.