← Vulnerability feed

Vulnerability record · CVE-2004-1135 · published 10 January 2005

CVE-2004-1135: WS_FTP Server FTP command buffer overflows crash service

Ipswitch · Ws Ftp Server

WS_FTP Server 5.03 (2004.10.14) contains multiple buffer overflows reachable through long SITE, XMKD, MKD and RNFR FTP commands. The record describes only a denial-of-service outcome (service crash), not code execution, so the practical risk is availability loss rather than host compromise.

5.0 CVSS 2.0 Medium EPSS 50% · top 1.1%
5.0CVSS 2.0 base score
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

medium priorityRemote unauthenticated denial of service with public exploit code and high EPSS, but impact is limited to service availability and the affected product is a long-obsolete release.

What it is

WS_FTP Server 5.03 (2004.10.14) contains multiple buffer overflows reachable through long SITE, XMKD, MKD and RNFR FTP commands. The record describes only a denial-of-service outcome (service crash), not code execution, so the practical risk is availability loss rather than host compromise.

Impact

A remote attacker can crash the WS_FTP Server service, interrupting file transfer availability for all users. No confidentiality or integrity impact is stated in the CVSS vector.

Attack surface

Reachable over the network via the FTP service by sending oversized SITE, XMKD, MKD or RNFR commands. The CVSS vector AV:N/AC:L/Au:N indicates no authentication is required and no user interaction is needed.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high at roughly 0.50 (98.8th percentile), and the references include a public exploit write-up on Securiteam, indicating public proof-of-concept availability.

What to do

  • Upgrade WS_FTP Server to a version later than 5.03 2004.10.14; the record does not name a fixed version, so confirm with the vendor.
  • If patching is not possible, restrict FTP access to trusted networks and disable or filter SITE, XMKD, MKD and RNFR commands where the server configuration allows.
  • Place the FTP service behind a filtering proxy or IPS that rejects abnormally long FTP command arguments.
  • Monitor the service for repeated crashes and restart automatically to limit downtime.
  • Retire or isolate the end-of-life 5.03 release, which is no longer supported.

Detection

  • Alert on FTP command lines exceeding normal length for SITE, XMKD, MKD or RNFR in server or IDS logs.
  • Monitor WS_FTP Server process crashes and unexpected service restarts.
  • Baseline normal FTP command argument lengths and flag outliers from external source IPs.
  • Review network logs for repeated malformed FTP commands from a single source.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-1135 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-12144Ipswitch ws ftp server path traversal vulnerabilityAn issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Attackers have the ability to abuse a path traversa…EPSS 2.9%9.1CVE-2019-12146Ipswitch ws ftp server path traversal vulnerabilityA Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Attackers have the ability to ab…EPSS 4.0%7.5CVE-2019-12145Ipswitch ws ftp server path traversal vulnerabilityA Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. An attacker can supply a string …EPSS 4.7%7.5CVE-2006-4974Ipswitch ws ftp server vulnerabilityBuffer overflow in Ipswitch WS_FTP Limited Edition (LE) 5.08 allows remote FTP servers to execute arbitrary code via a long response to a PASV comman…EPSS 4.2%7.5CVE-2004-1884Ipswitch ws ftp pro vulnerabilityIpswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access.EPSS 5.8%7.5CVE-2003-0772WS_FTP Server buffer overflows in APPE and STAT commandsWS_FTP 3 and 4 contain multiple buffer overflows reachable through long APPE (append) or STAT (status) command arguments. A remote authenticated user…EPSS 85%analysed6.8CVE-2007-0666Ipswitch ws ftp server vulnerabilityIpswitch WS_FTP Server 5.04 allows FTP site administrators to execute arbitrary code on the system via a long input string to the (1) iFTPAddU or (2)…EPSS 1.9%6.5CVE-2006-5000WS_FTP Server buffer overflows in XCRC, XMD5 and XSHA1 commandsWS_FTP Server 5.05 before Hotfix 1, and possibly versions back to 5.0, contains multiple buffer overflows reachable through the XCRC, XMD5 and XSHA1 …EPSS 65%analysed

Source: NIST National Vulnerability Database (record CVE-2004-1135), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.