CVE-2008-7016Cross-Site Request Forgery in Mewburn Tnftpd

Severity
6.8MEDIUMNVD
EPSS
0.2%
top 53.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 21
Latest updateMay 17

Description

tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unknown vectors, probably involving a crafted ftp:// link to a tnftpd server.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages1 packages

NVDluke_mewburn/tnftpd20040810, 20061217, 20080609+2

🔴Vulnerability Details

2
GHSA
GHSA-vrx7-4ch8-xhvx: tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF)2022-05-17
CVEList
CVE-2008-7016: tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF)2009-08-21
CVE-2008-7016 — Cross-Site Request Forgery | cvebase