CVE-2008-7016: CSRF
tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unknown vectors, probably involving a crafted ftp:// link to a tnftpd server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-7016?
CVE-2008-7016 is classified as a medium severity vulnerability due to its potential for cross-site request forgery (CSRF) attacks.
How do I fix CVE-2008-7016?
To mitigate CVE-2008-7016, upgrade to a version of tnftpd released after 20080929 that does not have this vulnerability.
What versions of tnftpd are affected by CVE-2008-7016?
CVE-2008-7016 affects tnftpd versions 20040810, 20061217, and 20080609.
What type of attack is associated with CVE-2008-7016?
CVE-2008-7016 is associated with cross-site request forgery (CSRF) attacks.
Is CVE-2008-7016 still a threat today?
While specific instances of CVE-2008-7016 may no longer be prevalent, any vulnerable systems that haven’t been updated remain a risk.