VYPR
Unrated severityNVD Advisory· Published Dec 6, 2004· Updated Apr 16, 2026

CVE-2004-0448

CVE-2004-0448

Description

Format string vulnerability in the log function for jftpgw 0.13.4 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in certain syslog messages.

Affected products

4
  • Jftpgw/Jftpgw4 versions
    cpe:2.3:a:jftpgw:jftpgw:0.13:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:jftpgw:jftpgw:0.13:*:*:*:*:*:*:*
    • cpe:2.3:a:jftpgw:jftpgw:0.13.1:*:*:*:*:*:*:*
    • cpe:2.3:a:jftpgw:jftpgw:0.13.2:*:*:*:*:*:*:*
    • cpe:2.3:a:jftpgw:jftpgw:0.13.3:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.