Skip to content
Noroxi

glftpd records

7 published records for vendor glftpd.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 22

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

All records

7 records
  • The privpath directive in glftpd 1.18 allows remote attackers to bypass access restrictions for directories by using the file name completio

    CriticalCVSS 10.0No exploitEPSS 4%

    glftpd · glftpdJun 26, 2000

  • glFtpD allows local users to gain privileges via metacharacters in the SITE ZIPCHK command.

    CriticalCVSS 10.0No exploitEPSS 2%

    glftpd · glftpdDec 23, 1999

  • CVE-2000-0038
    32Monitor

    glFtpD includes a default glftpd user account with a default password and a UID of 0.

    HighCVSS 7.5Proof of conceptEPSS 7%

    glftpd · glftpdDec 23, 1999

  • An issue was discovered in glFTPd 2.11a that allows remote attackers to cause a denial of service via exceeding the connection limit.

    HighCVSS 7.5No exploitEPSS 2%

    glftpd · glftpdJul 7, 2022

  • CVE-2006-1253
    30Monitor

    Unspecified vulnerability in glFTPd before 2.01 RC5 allows remote attackers to bypass IP checks via a crafted DNS hostname, possibly a hostn

    HighCVSS 7.5No exploitEPSS 2%

    glftpd · glftpdMar 18, 2006

  • CVE-2001-0965
    22Monitor

    glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument that contains a large

    MediumCVSS 5.0Proof of conceptEPSS 7%

    glftpd · glftpdAug 31, 2001

  • CVE-2005-0483
    21Monitor

    Multiple directory traversal vulnerabilities in sitenfo.sh, sitezipchk.sh, and siteziplist.sh in Glftpd 1.26 to 2.00 allow remote authentica

    MediumCVSS 5.0No exploitEPSS 2%

    glftpd · glftpdMar 30, 2005