peter bassill · operator
$ cve CVE-2004-1118 JSON

CVE-2004-1118 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 8.2% (pctl 95)

Patch early

A public exploit exists.

Description

Buffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.0.0.10, and possibly other applications, allows remote attackers to execute arbitrary code via a long filename.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS8.18% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2005-01-10
Last modified2026-06-16

Affected (1)

VendorProduct
weonlydowodftpdlx activex component

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD