Total vulnerabilities in the database
tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unknown vectors, probably involving a crafted ftp:// link to a tnftpd server.
Software | From | Fixed in |
---|---|---|
luke_mewburn / tnftpd | 20061217 | 20061217.x |
luke_mewburn / tnftpd | 20040810 | 20040810.x |
luke_mewburn / tnftpd | 20080609 | 20080609.x |