Cooolsoft develops a focused line of FTP client and server applications, including PowerFTP and Personal FTP Server, that serve a niche segment of file-transfer users. The vendor's disclosures cluster around its FTP implementations and frequently acquire public exploit code, reflecting the direct accessibility of these network services. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cooolsoft over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0932HIGH Buffer overflow in Cooolsoft PowerFTP Server 2.03 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long command. | Nov 28, 2001 | 7.5 | 41 | NO | YES |
CVE-2002-1522MEDIUM Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long USER a | Apr 2, 2003 | 5.0 | 28 | NO | YES |
CVE-2001-0931HIGH Directory traversal vulnerability in Cooolsoft PowerFTP Server 2.03 allows attackers to list or read arbitrary files and directories via a .. (dot dot) in (1) LS or (2) GET. | Nov 28, 2001 | 7.5 | 22 | NO | NO |
CVE-2001-0933HIGH Cooolsoft PowerFTP Server 2.03 allows remote attackers to list the contents of arbitrary drives via a ls (LIST) command that includes the drive letter as an argument, e.g. "ls C:". | Nov 28, 2001 | 7.5 | 22 | NO | NO |
CVE-2001-0934HIGH Cooolsoft PowerFTP Server 2.03 allows remote attackers to obtain the physical path of the server root via the pwd command, which lists the full pathname. | Nov 28, 2001 | 7.5 | 22 | NO | NO |
CVE-2002-0264HIGH PowerFTP Personal FTP Server 2.03 through 2.10 stores sensitive account information in plaintext in the ftpserver.ini file, which allows attackers with access to the file to gain p | May 29, 2002 | 7.5 | 21 | NO | NO |
CVE-2003-0271HIGH Buffer overflow in Personal FTP Server allows remote attackers to execute arbitrary code via a long USER argument. | May 27, 2003 | 7.5 | 20 | NO | NO |
CVE-2002-1545MEDIUM CooolSoft Personal FTP Server 2.24 allows remote attackers to obtain the absolute pathname of the FTP root via a PWD command, which includes the full path in the response. | Mar 31, 2003 | 5.0 | 19 | NO | NO |
CVE-2002-1544MEDIUM Directory traversal vulnerability in CooolSoft Personal FTP Server 2.24 allows remote attackers to read or modify arbitrary files via .. (dot dot) sequences in the commands (1) LIS | Mar 31, 2003 | 6.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cooolsoft.
Media articles that mention a CVE ID that affects a product developed by Cooolsoft — matched by CVE ID, not by vendor name.