{"api_version":"1","generated_at":"2026-05-11T15:41:54+00:00","cve":"CVE-2004-1118","urls":{"html":"https://cve.report/CVE-2004-1118","api":"https://cve.report/api/cve/CVE-2004-1118.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-1118","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-1118"},"summary":{"title":"CVE-2004-1118","description":"Buffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.0.0.10, and possibly other applications, allows remote attackers to execute arbitrary code via a long filename.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-01-10 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029243.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029243.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[Full-Disclosure] WeOnlyDo! COM Ftp DELUXE ActiveX Control Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029244.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029244.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[Full-Disclosure] CoffeeCup FTP Clients Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/11721","name":"http://www.securityfocus.com/bid/11721","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"WeOnlyDo! wodFtpDLX ActiveX Component Remote Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=110114233323417&w=2","name":"http://marc.info/?l=bugtraq&m=110114233323417&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'WeOnlyDo! COM Ftp DELUXE ActiveX Control Buffer Overflow Vulnerability' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18190","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18190","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-1118","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1118","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"1118","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"weonlydo","cpe5":"wodftpdlx_activex_component","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1118","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"weonlydo","cpe5":"wodftpdlx_activex_component","cpe6":"2.1.1_8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:39:00.818Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"11721","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/11721"},{"name":"20041122 WeOnlyDo! COM Ftp DELUXE ActiveX Control Buffer Overflow Vulnerability","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029243.html"},{"name":"20041122 WeOnlyDo! COM Ftp DELUXE ActiveX Control Buffer Overflow Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=110114233323417&w=2"},{"name":"20041122 CoffeeCup FTP Clients Buffer Overflow Vulnerability","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029244.html"},{"name":"wodftpdlx-long-filename-bo(18190)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18190"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-11-22T00:00:00.000Z","descriptions":[{"lang":"en","value":"Buffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.0.0.10, and possibly other applications, allows remote attackers to execute arbitrary code via a long filename."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"11721","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/11721"},{"name":"20041122 WeOnlyDo! COM Ftp DELUXE ActiveX Control Buffer Overflow Vulnerability","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029243.html"},{"name":"20041122 WeOnlyDo! COM Ftp DELUXE ActiveX Control Buffer Overflow Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=110114233323417&w=2"},{"name":"20041122 CoffeeCup FTP Clients Buffer Overflow Vulnerability","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029244.html"},{"name":"wodftpdlx-long-filename-bo(18190)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18190"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-1118","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Buffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.0.0.10, and possibly other applications, allows remote attackers to execute arbitrary code via a long filename."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"11721","refsource":"BID","url":"http://www.securityfocus.com/bid/11721"},{"name":"20041122 WeOnlyDo! COM Ftp DELUXE ActiveX Control Buffer Overflow Vulnerability","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029243.html"},{"name":"20041122 WeOnlyDo! COM Ftp DELUXE ActiveX Control Buffer Overflow Vulnerability","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=110114233323417&w=2"},{"name":"20041122 CoffeeCup FTP Clients Buffer Overflow Vulnerability","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/029244.html"},{"name":"wodftpdlx-long-filename-bo(18190)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18190"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-1118","datePublished":"2004-12-01T05:00:00.000Z","dateReserved":"2004-11-30T00:00:00.000Z","dateUpdated":"2024-08-08T00:39:00.818Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-01-10 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:weonlydo:wodftpdlx_activex_component:*:*:*:*:*:*:*:*","matchCriteriaId":"04FE4BB0-AC3E-4E85-8C2E-7D75B4900F76"},{"vulnerable":true,"criteria":"cpe:2.3:a:weonlydo:wodftpdlx_activex_component:2.1.1_8:*:*:*:*:*:*:*","matchCriteriaId":"6902BB56-365D-43F9-9EFC-248BA73AEFC9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"1118","Ordinal":"1","Title":"CVE-2004-1118","CVE":"CVE-2004-1118","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"1118","Ordinal":"1","NoteData":"Buffer overflow in the WodFtpDLX.ocx (WeOnlyDo!) ActiveX component before 2.3.2.97, as used by CoffeeCup Direct FTP 6.2.0.62 and CoffeeCup Free FTP 3.0.0.10, and possibly other applications, allows remote attackers to execute arbitrary code via a long filename.","Type":"Description","Title":"CVE-2004-1118"},{"CveYear":"2004","CveId":"1118","Ordinal":"2","NoteData":"2004-12-01","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"1118","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}