CVE-2008-4247
Summary
| CVE | CVE-2008-4247 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-09-25 19:25:18 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via a long ftp:// URI that leverages an existing session from the FTP client implementation in a web browser. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-014.txt.asc | af854a3a-2127-422b-91ae-364da2661108 | ftp.netbsd.org | |
| Oracle Critical Patch Update Pre-Release Announcement - October 2010 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| security.FreeBSD.org/advisories/FreeBSD-SA-08:12.ftpd.asc | af854a3a-2127-422b-91ae-364da2661108 | security.FreeBSD.org | |
| NetBSD ftpd Long Command Processing Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVS Repository | af854a3a-2127-422b-91ae-364da2661108 | www.openbsd.org | |
| multiple vendor ftpd - Cross-site request forgery - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Bug 3115 – Cross-site request forgery | af854a3a-2127-422b-91ae-364da2661108 | bugs.proftpd.org | |
| NetBSD ftpd Request Processing Bug Permits Cross-Site Request Forgery Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVS Repository | af854a3a-2127-422b-91ae-364da2661108 | www.openbsd.org | |
| FreeBSD ftpd Long Command Processing Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| src/libexec/ftpd/ftpcmd.y - diff - 1.52 | af854a3a-2127-422b-91ae-364da2661108 | www.openbsd.org | Exploit |
| SecurityTracker: BSD ftpd Request Processing Bug Permits Cross-Site Request Forgery Attacks | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| OpenBSD ftpd Long Command Processing Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityReason - multiple vendor ftpd - Cross-site request forgery ( Research Advisory ) | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| src/libexec/ftpd/ftpd.c - diff - 1.184 | af854a3a-2127-422b-91ae-364da2661108 | www.openbsd.org | Exploit |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.