CVE-2001-1021 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 42.1% (pctl 99)
Patch early
A public exploit exists.
Description
Buffer overflows in WS_FTP 2.02 allow remote attackers to execute arbitrary code via long arguments to (1) DELE, (2) MDTM, (3) MLST, (4) MKD, (5) RMD, (6) RNFR, (7) RNTO, (8) SIZE, (9) STAT, (10) XMKD, or (11) XRMD.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 42.14% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2001-07-26 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| progress | ws ftp server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Ipswitch WS_FTP Server 5.03 - 'RNFR' Buffer Overflow | 2004-11-29 |
| exploit-db | Ipswitch WS_FTP Server 2.0 - Anonymous Multiple FTP Command Buffer Overflows | 2001-07-25 |
References
- http://archives.neohapsis.com/archives/bugtraq/2001-07/0610.html
- http://www.ipswitch.com/Support/WS_FTP-Server/patch-upgrades.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6911
- http://archives.neohapsis.com/archives/bugtraq/2001-07/0610.html
- http://www.ipswitch.com/Support/WS_FTP-Server/patch-upgrades.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6911
→ the Explorer · watch your stack · NVD