peter bassill · operator
$ cve CVE-2008-4247 JSON

CVE-2008-4247 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 5.3% (pctl 92)

Patch early

A public exploit exists.

Description

ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via a long ftp:// URI that leverages an existing session from the FTP client implementation in a web browser.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS5.25% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2008-09-25
Last modified2026-06-16

Affected (3)

VendorProduct
freebsdfreebsd
netbsdnetbsd
openbsdopenbsd

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD