Back

CVE-2004-0448

Format string vulnerability in the log function for jftpgw 0.13.4 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in certain syslog messages.

Published: Dec 6, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (4)

Vendor Product Version
jftpgw jftpgw 0.13
jftpgw jftpgw 0.13.1
jftpgw jftpgw 0.13.2
jftpgw jftpgw 0.13.3

GitHub Security Advisory GHSA-3m3c-pvwf-4p64

Format string vulnerability in the log function for jftpgw 0.13.4 and earlier allows remote...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 4.34%

Top 10% most likely to be exploited

Threat Score 41.3 / 100

Data Sources

NVD EPSS GitHub