CVE-2004-1118 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 8.2% (pctl 95)
Patch early
A public exploit exists.
Description
Buffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.0.0.10, and possibly other applications, allows remote attackers to execute arbitrary code via a long filename.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 8.18% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-01-10 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| weonlydo | wodftpdlx activex component |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | wodFtpDLX Client - ActiveX Control Buffer Overflow Crash | 2004-11-22 |
| exploit-db | CoffeeCup FTP Clients (Direct 6.2.0.62) (Free 3.0.0.10) - Remote Buffer Overflow | 2004-11-22 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029243.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029244.html
- http://marc.info/?l=bugtraq&m=110114233323417&w=2
- http://www.securityfocus.com/bid/11721
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18190
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029243.html
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029244.html
- http://marc.info/?l=bugtraq&m=110114233323417&w=2
- http://www.securityfocus.com/bid/11721
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18190
→ the Explorer · watch your stack · NVD