Wzdftpd.SITE.Arbitrary.Command.Execution

description-logoDescription

Indicates an attacker tried to issue unauthorized commands by exploiting a vulnerability in Wxdftpd. Wzdftpd is a ftp server designed to be modular, work under linux/win32/freebsd/openbsd, and to be entirely configurable online using SITE commands. Wzdftpd contains a vulnerability which allows unauthorized users to issue arbitrary commands using the "|" or ";" characters that could allow malicious attackers access to the system.

affected-products-logoAffected Products

wzdftpd 0.5.4 and earlier.

Impact logoImpact

Issue arbitrary commands against the service potentially leading to the compromise of the system.

recomended-action-logoRecommended Actions

Update to wzdftp version 0.5.5 or newer.
http://www.wzdftpd.net

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)