wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted as an argument to the program that does the conversion, e.g. tar or uncompress.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Anonftp | Millenux_gmbh | 2.8.1 (including) | 2.8.1 (including) |
Wu-ftpd | University_of_washington | 2.4.2 (including) | 2.4.2 (including) |
Wu-ftpd | University_of_washington | 2.5.0 (including) | 2.5.0 (including) |
Wu-ftpd | University_of_washington | 2.6.0 (including) | 2.6.0 (including) |