← Vulnerability feed

Vulnerability record · CVE-2006-5826 · published 10 November 2006

CVE-2006-5826: Texas imperial software wftpd vulnerability

TTexas Imperial Software · Wftpd

Buffer overflow in Texas Imperial Software WFTPD Pro Server 3.23.1.1 allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) via crafted APPE commands that contain "/" (slash) or "\" (backslash) characters.

5.8 CVSS 2.0 Medium EPSS 11% · top 4.3%
5.8CVSS 2.0 base score
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in Texas Imperial Software WFTPD Pro Server 3.23.1.1 allows remote authenticated users to execute arbitrary code or cause a denial of service (application crash) via crafted APPE commands that contain "/" (slash) or "\" (backslash) characters.

AV:N/AC:L/Au:M/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-5826 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-1999-0950Texas imperial software wftpd vulnerabilityBuffer overflow in WFTPD FTP server allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.EPSS 8.1%7.5CVE-2001-0694Texas imperial software wftpd vulnerabilityDirectory traversal vulnerability in WFTPD 3.00 R5 allows a remote attacker to view arbitrary files via a dot dot attack in the CD command.EPSS 1.6%7.2CVE-2004-0340Texas imperial software wftpd vulnerabilityStack-based buffer overflow in WFTPD Pro Server 3.21 Release 1, Pro Server 3.20 Release 2, Server 3.21 Release 1, and Server 3.10 allows local users …EPSS 1.3%6.5CVE-2006-4318WFTPD Server buffer overflow via long SIZE commandsWFTPD Server 3.23 contains a buffer overflow that is triggered by long SIZE commands sent to the FTP service. A remote attacker can corrupt memory an…EPSS 62%analysed6.4CVE-2000-0645Texas imperial software wftpd vulnerabilityWFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a fil…EPSS 4.9%5.0CVE-2007-0311Texas imperial software wftpd vulnerabilityTexas Imperial Software WFTPD and WFTPD Pro Server 3.25 and earlier allow remote attackers to cause a denial of service (application crash) via a lon…EPSS 2.8%5.0CVE-2004-1642Texas imperial software wftpd vulnerabilityWFTPD Pro Server 3.21 allows remote authenticated users to cause a denial of service (crash) via a series of long MLIST commands.EPSS 3.1%5.0CVE-2001-0695Texas imperial software wftpd vulnerabilityWFTPD 3.00 R5 allows a remote attacker to cause a denial of service by making repeated requests to cd to the floppy drive (A:\).EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2006-5826), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.