CVE-2008-7016 Information

Description

tnftpd before 20080929 splits large command strings into multiple commands which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unknown vectors probably involving a crafted ftp:// link to a tnftpd server.

Reference

http://freshmeat.net/projects/tnftpd/?branch_id=14355&release_id=285654 http://osvdb.org/48637 http://secunia.com/advisories/31958 https://exchange.xforce.ibmcloud.com/vulnerabilities/45534 tnftpd-url-csrf(45534)

Share on: