Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-4247
Description:ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via a long ftp:// URI that leverages an existing session from the FTP client implementation in a web browser.
Test IDs: 1.3.6.1.4.1.25623.1.0.63078   1.3.6.1.4.1.25623.1.0.63175  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-4247
FreeBSD Security Advisory: FreeBSD-SA-08:12
http://security.FreeBSD.org/advisories/FreeBSD-SA-08:12.ftpd.asc
http://bugs.proftpd.org/show_bug.cgi?id=3115
NETBSD Security Advisory: NetBSD-SA2008-014
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2008-014.txt.asc
http://www.securitytracker.com/id?1020946
http://www.securitytracker.com/id?1021112
http://secunia.com/advisories/32068
http://secunia.com/advisories/32070
http://secunia.com/advisories/33341
http://securityreason.com/securityalert/4313
http://securityreason.com/achievement_securityalert/56




© 1998-2025 E-Soft Inc. All rights reserved.