PT-2009-5771 · Mozilla · Fireftp Extension
Tan Chew Keong
·
Published
2009-09-29
·
Updated
2024-03-12
·
CVE-2009-3478
CVSS v2.0
6.0
Medium
| Vector | AV:N/AC:M/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
FireFTP Extension version 1.0.5
Description
The issue allows remote authenticated SFTP users to manipulate victims into altering permissions, deleting, downloading, or moving the wrong file. This is achieved by using a filename containing double quotes, which is not properly filtered or encoded when constructing the command to send to psftp.exe. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations
For FireFTP Extension version 1.0.5, consider disabling the use of double quotes in filenames as a temporary workaround until a patch is available. Restrict access to the
sftp.js and controlSocket.js.in files to minimize the risk of exploitation. Avoid using filenames with double quotes in the affected API endpoints until the issue is resolved.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fireftp Extension