Unrated severityNVD Advisory· Published Sep 25, 2008· Updated Apr 23, 2026
CVE-2008-4242
CVE-2008-4242
Description
ProFTPD 1.3.1 interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via a long ftp:// URI that leverages an existing session from the FTP client implementation in a web browser.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
13- www.securityfocus.com/bid/31289nvdExploit
- secunia.com/advisories/31930nvdVendor Advisory
- bugs.proftpd.org/show_bug.cginvd
- secunia.com/advisories/33261nvd
- secunia.com/advisories/33413nvd
- securityreason.com/achievement_securityalert/56nvd
- securityreason.com/securityalert/4313nvd
- www.debian.org/security/2008/dsa-1689nvd
- www.mandriva.com/security/advisoriesnvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/45274nvd
- www.redhat.com/archives/fedora-package-announce/2009-January/msg00078.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2009-January/msg00245.htmlnvd
News mentions
0No linked articles in our index yet.