CVE-2008-4247 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 5.3% (pctl 92)
Patch early
A public exploit exists.
Description
ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via a long ftp:// URI that leverages an existing session from the FTP client implementation in a web browser.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 5.25% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-352 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-09-25 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| freebsd | freebsd |
| netbsd | netbsd |
| openbsd | openbsd |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Multiple Vendor FTP Server - Long Command Handling Security | 2008-09-20 |
References
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-014.txt.asc
- http://bugs.proftpd.org/show_bug.cgi?id=3115
- http://secunia.com/advisories/32068
- http://secunia.com/advisories/32070
- http://secunia.com/advisories/33341
- http://security.FreeBSD.org/advisories/FreeBSD-SA-08:12.ftpd.asc
- http://securityreason.com/achievement_securityalert/56
- http://securityreason.com/securityalert/4313
- http://www.openbsd.org/cgi-bin/cvsweb/src/libexec/ftpd/ftpcmd.y
- http://www.openbsd.org/cgi-bin/cvsweb/src/libexec/ftpd/ftpcmd.y.diff?r1=1.51&r2=1.52&f=h
- http://www.openbsd.org/cgi-bin/cvsweb/src/libexec/ftpd/ftpd.c
- http://www.openbsd.org/cgi-bin/cvsweb/src/libexec/ftpd/ftpd.c.diff?r1=1.183&r2=1.184&f=h
- http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html
- http://www.securitytracker.com/id?1020946
- http://www.securitytracker.com/id?1021112
- ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-014.txt.asc
- http://bugs.proftpd.org/show_bug.cgi?id=3115
- http://secunia.com/advisories/32068
- http://secunia.com/advisories/32070
- http://secunia.com/advisories/33341
→ the Explorer · watch your stack · NVD