CVE-2008-4247

EUVD-2008-4230
ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via a long ftp:// URI that leverages an existing session from the FTP client implementation in a web browser.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
Affected Products (NVD)
VendorProductVersion
freebsdfreebsd
7.0
netbsdnetbsd
4.0
openbsdopenbsd
4.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
linux-ftpd
bookworm
0.17-37
fixed
bullseye
0.17-36.2
fixed
etch
no-dsa
linux-ftpd-ssl
bookworm
0.17.36+really0.17-2
fixed
bullseye
0.17.36+0.3-2.2
fixed
etch
no-dsa
sid
0.17.36+really0.17-3
fixed
References