← Back

Eftp

eftp

Vendor: Khamil Landross And Zack Jones • 7 CVEs

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Khamil Landross And Zack Jones
1Eftp
Apr 16, 2026
Dec 13, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in EFTP 2.0.8.346 allows local users to read directories via a ... (modified dot dot) in the CWD command.
1Khamil Landross And Zack Jones
1Eftp
Apr 16, 2026
Sep 12, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in EFTP 2.0.7.337 allows remote attackers to execute arbitrary code by uploading a .lnk file containing a large number of characters.
1Khamil Landross And Zack Jones
1Eftp
Apr 16, 2026
Sep 12, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
EFTP 2.0.7.337 stores user passwords in plaintext in the eftp2users.dat file.
1Khamil Landross And Zack Jones
1Eftp
Apr 16, 2026
Sep 12, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
EFTP 2.0.7.337 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and al...Show more
EFTP 2.0.7.337 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.Show less
1Khamil Landross And Zack Jones
1Eftp
Apr 16, 2026
Sep 12, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST, (2) QUOTE SIZE, and (3) QUOTE MDTM commands.
1Khamil Landross And Zack Jones
1Eftp
Apr 16, 2026
Nov 14, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in EFTP allows remote attackers to cause a denial of service by sending a string that does not contain a newline, then disconnecting from the server.
1Khamil Landross And Zack Jones
1Eftp
Apr 16, 2026
Nov 14, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in EFTP allows remote attackers to cause a denial of service via a long string.