← Vulnerability feed

Vulnerability record · CVE-2006-2961 · published 12 June 2006

CVE-2006-2961: CesarFTP MKD command stack buffer overflow

Aclogic · Cesarftp

CesarFTP 0.99g and earlier contains a stack-based buffer overflow reachable through a long MKD command. A remote attacker can crash the FTP service and possibly execute arbitrary code. The record notes the provenance of the details is unknown and they come from third-party information, so the description is thin.

7.5 CVSS 2.0 High EPSS 62% · top 0.9%
7.5CVSS 2.0 base score
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in CesarFTP 0.99g and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MKD command. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote, unauthenticated, low-complexity overflow with partial code execution potential and very high EPSS, though the product is old and no KEV listing exists.

What it is

CesarFTP 0.99g and earlier contains a stack-based buffer overflow reachable through a long MKD command. A remote attacker can crash the FTP service and possibly execute arbitrary code. The record notes the provenance of the details is unknown and they come from third-party information, so the description is thin.

Impact

An attacker gains denial of service against the FTP server and potentially arbitrary code execution in the context of the CesarFTP process. The CVSS 2.0 vector rates partial confidentiality, integrity and availability impact.

Attack surface

The flaw is reached over the network via the FTP protocol by sending an oversized MKD command; the AV:N/AC:L/Au:N vector indicates no authentication and no user interaction are required. Any host exposing the CesarFTP service is directly reachable.

Exploitation

CVE-2006-2961 is not listed in CISA KEV and no ransomware usage is documented, but EPSS is 0.61673 (99.13 percentile), indicating a high modeled likelihood of exploitation activity. References are vendor advisories and third-party databases with no public exploit tag.

What to do

  • Upgrade or replace CesarFTP 0.99g and earlier; the product is long unmaintained, so migration to a supported FTP server is the durable fix.
  • If the service must remain, restrict FTP access to trusted networks and disable anonymous access.
  • Enforce strict length validation on FTP command arguments at the perimeter where possible.
  • Run the FTP service under a low-privilege account and isolate it from sensitive data and management networks.
  • Monitor vendor and CVE feeds for a patched release, since no fixed version is identified in this record.

Detection

  • Alert on MKD commands with abnormally long argument strings in FTP logs or network captures.
  • Monitor for CesarFTP process crashes or unexpected restarts on FTP hosts.
  • Watch for post-crash shell or child process creation from the FTP service account.
  • Baseline normal MKD usage and flag deviations in command length or frequency.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-2961 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2006-2961), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.