← Vulnerability feed

Vulnerability record · CVE-2006-4318 · published 24 August 2006

CVE-2006-4318: WFTPD Server buffer overflow via long SIZE commands

TTexas Imperial Software · Wftpd

WFTPD Server 3.23 contains a buffer overflow that is triggered by long SIZE commands sent to the FTP service. A remote attacker can corrupt memory and potentially execute arbitrary code on the server. The flaw is in an old FTP server product, but public exploit code exists and the EPSS score is high.

6.5 CVSS 2.0 Medium EPSS 62% · top 0.8%
6.5CVSS 2.0 base score
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityPublic exploit code exists and EPSS is very high, but the CVSS vector requires authentication, reducing the attack surface compared to an unauthenticated flaw.

What it is

WFTPD Server 3.23 contains a buffer overflow that is triggered by long SIZE commands sent to the FTP service. A remote attacker can corrupt memory and potentially execute arbitrary code on the server. The flaw is in an old FTP server product, but public exploit code exists and the EPSS score is high.

Impact

An attacker who can authenticate to the FTP service may execute arbitrary code with the privileges of the WFTPD process. This could lead to full compromise of the host running the FTP server.

Attack surface

The vulnerability is reached over the network through the FTP control channel by sending a crafted SIZE command. The CVSS vector indicates authentication is required (Au:S), so the attacker must have valid FTP credentials; no user interaction is needed.

Exploitation

Public exploit code is referenced in SecurityFocus, SecurityTracker and Exploit-DB, and EPSS is 0.62409 (99th percentile), indicating a high likelihood of exploitation. The CVE is not listed in CISA KEV.

What to do

  • Upgrade WFTPD Server to a version later than 3.23 if available, or migrate to a supported FTP server.
  • Restrict network access to the FTP service to trusted hosts and require strong authentication.
  • Disable or block the SIZE command if the FTP server configuration allows command filtering.
  • Monitor vendor advisories and apply any available patches or workarounds promptly.

Detection

  • Inspect FTP server logs for SIZE commands with unusually long arguments.
  • Use network IDS/IPS signatures to detect oversized SIZE commands on FTP control channels.
  • Monitor for unexpected process crashes or restarts of the WFTPD service.
  • Correlate FTP authentication logs with subsequent anomalous process activity on the server.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-4318 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-1999-0950Texas imperial software wftpd vulnerabilityBuffer overflow in WFTPD FTP server allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.EPSS 8.1%7.5CVE-2001-0694Texas imperial software wftpd vulnerabilityDirectory traversal vulnerability in WFTPD 3.00 R5 allows a remote attacker to view arbitrary files via a dot dot attack in the CD command.EPSS 1.6%7.2CVE-2004-0340Texas imperial software wftpd vulnerabilityStack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users …EPSS 1.3%6.4CVE-2000-0645Texas imperial software wftpd vulnerabilityWFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a fil…EPSS 4.9%5.8CVE-2006-5826Texas imperial software wftpd vulnerabilityBuffer overflow in Texas Imperial Software WFTPD Pro Server 3.23.1.1 allows remote authenticated users to execute arbitrary code or cause a denial of…EPSS 11%5.0CVE-2007-0311Texas imperial software wftpd vulnerabilityTexas Imperial Software WFTPD and WFTPD Pro Server 3.25 and earlier allow remote attackers to cause a denial of service (application crash) via a lon…EPSS 2.8%5.0CVE-2004-1642Texas imperial software wftpd vulnerabilityWFTPD Pro Server 3.21 allows remote authenticated users to cause a denial of service (crash) via a series of long MLIST commands.EPSS 3.1%5.0CVE-2001-0695Texas imperial software wftpd vulnerabilityWFTPD 3.00 R5 allows a remote attacker to cause a denial of service by making repeated requests to cd to the floppy drive (A:\).EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2006-4318), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.