PT-2009-2485 · Netbsd · Tnftpd
Published
2009-08-21
·
Updated
2017-08-17
·
CVE-2008-7016
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
tnftpd versions prior to 20080929
Description
The issue allows remote attackers to conduct cross-site request forgery (CSRF) attacks. This is achieved by splitting large command strings into multiple commands, probably involving a crafted ftp:// link to a tnftpd server.
Recommendations
For versions prior to 20080929, update to a version released after 20080929 to resolve the issue. As a temporary workaround, consider restricting access to the tnftpd server to minimize the risk of exploitation.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tnftpd