{"api_version":"1","generated_at":"2026-07-23T06:51:52+00:00","cve":"CVE-2004-0069","urls":{"html":"https://cve.report/CVE-2004-0069","api":"https://cve.report/api/cve/CVE-2004-0069.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-0069","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-0069"},"summary":{"title":"CVE-2004-0069","description":"Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-02-17 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securitytracker.com/id?1008658","name":"http://www.securitytracker.com/id?1008658","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Windows Ftp Server Format String Flaw May Let Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=107401398014761&w=2","name":"http://marc.info/?l=bugtraq&m=107401398014761&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'exploit for HD Soft Windows FTP Server 1.6' - MARC","mime":"text/x-c","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=107367110805273&w=2","name":"http://marc.info/?l=bugtraq&m=107367110805273&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Windows FTP Server Format String Vulnerability' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/9385","name":"http://www.securityfocus.com/bid/9385","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"HD Soft Windows FTP Server Username Format String Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-0069","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-0069","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"69","vulnerable":"1","versionEndIncluding":"1.6","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hd_soft","cpe5":"windows_ftp_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:01:23.643Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20040108 Windows FTP Server Format String Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=107367110805273&w=2"},{"name":"9385","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/9385"},{"name":"20040113 exploit for HD Soft Windows FTP Server 1.6","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=107401398014761&w=2"},{"name":"1008658","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1008658"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-01-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-10-17T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20040108 Windows FTP Server Format String Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=107367110805273&w=2"},{"name":"9385","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/9385"},{"name":"20040113 exploit for HD Soft Windows FTP Server 1.6","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=107401398014761&w=2"},{"name":"1008658","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1008658"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-0069","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20040108 Windows FTP Server Format String Vulnerability","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=107367110805273&w=2"},{"name":"9385","refsource":"BID","url":"http://www.securityfocus.com/bid/9385"},{"name":"20040113 exploit for HD Soft Windows FTP Server 1.6","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=107401398014761&w=2"},{"name":"1008658","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1008658"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-0069","datePublished":"2004-01-15T05:00:00.000Z","dateReserved":"2004-01-15T00:00:00.000Z","dateUpdated":"2024-08-08T00:01:23.643Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-02-17 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hd_soft:windows_ftp_server:*:*:*:*:*:*:*:*","versionEndIncluding":"1.6","matchCriteriaId":"80729840-DAB9-4C89-B920-2A2F0D73EDDD"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"69","Ordinal":"1","Title":"CVE-2004-0069","CVE":"CVE-2004-0069","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"69","Ordinal":"1","NoteData":"Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.","Type":"Description","Title":"CVE-2004-0069"},{"CveYear":"2004","CveId":"69","Ordinal":"2","NoteData":"2004-01-15","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"69","Ordinal":"3","NoteData":"2016-10-17","Type":"Other","Title":"Modified"}]}}}