CVE-2000-0573
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command.
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command.
Affected Products
hp-uxhpResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
WU-FTPD - Site EXEC/INDEX Format String (Metasploit)
by Metasploit · Nov 30, 2010
WU-FTPD 2.6.0 - Remote Format Strings
by kalou · Jan 3, 2001
WU-FTPD 2.4.2/2.5 .0/2.6.0 - Remote Format String Stack Overwrite (3)
by justme · May 4, 2001
WU-FTPD 2.4.2/2.5 .0/2.6.0 - Remote Format String Stack Overwrite (2)
by vsz_ · Sep 26, 2000
WU-FTPD 2.4.2/2.5 .0/2.6.0 - Remote Format String Stack Overwrite (1)
by tf8 · Oct 15, 1999
WU-FTPD 2.6.0 - Remote Command Execution
by venglin · Nov 21, 2000
BeroFTPD 1.3.4(1) (Linux x86) - Remote Code Execution
by qitest1 · May 8, 2001
Frequently Asked Questions
Is CVE-2000-0573 in your stack?
O3 detects CVE-2000-0573 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.