Datawizard maintains a focused set of file-transfer and data-access products, including FTPXQ and WebXQ, that occupy a specialized niche despite their modest CVE volume. The vendor's disclosures frequently acquire public exploit code, reflecting the appeal of file-transfer services to adversaries, while the recurring weaknesses center on input-validation and related parsing issues endemic to protocol-handling software. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Datawizard over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0495MEDIUM Directory traversal in DataWizard WebXQ server 1.204 allows remote attackers to view files outside of the web root via a .. (dot dot) attack. | Jun 27, 2001 | 5.0 | 25 | NO | YES |
CVE-2001-0293MEDIUM Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command. | May 3, 2001 | 5.0 | 25 | NO | YES |
CVE-2006-5568MEDIUM FtpXQ Server 3.0.1 allows remote attackers to cause a denial of service (CPU exhaustion) via a long MKD command. | Oct 27, 2006 | 5.0 | 23 | NO | YES |
CVE-2009-3545MEDIUM DataWizard Technologies FtpXQ FTP Server 3.0 allows remote authenticated users to cause a denial of service (crash) via a long ABOR command. | Oct 5, 2009 | 4.0 | 22 | NO | YES |
CVE-2001-1213MEDIUM The default configuration of DataWizard FtpXQ 2.0 and 2.1 includes a default username and password, which allows remote attackers to read and write arbitrary files in the root fold | Dec 18, 2001 | 6.4 | 22 | NO | NO |
CVE-2006-5569MEDIUM FtpXQ Server 3.0.1 installs with two default testing accounts, which allows remote attackers to read or write arbitrary files via unknown vectors. NOTE: the provenance of this inf | Oct 27, 2006 | 6.4 | 17 | NO | NO |
CVE-2002-1920MEDIUM Buffer overflow in FtpXQ 2.5 allows remote attackers to cause a denial of service (crash) via a MKD command with a long directory name. | Dec 31, 2002 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Datawizard.
Media articles that mention a CVE ID that affects a product developed by Datawizard — matched by CVE ID, not by vendor name.