AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2008-4247

HIGH · CVSS 7.5 EPSS 4.04%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-09-25 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2008-4247
Severity
HIGH
CVSS
7.5
EPSS
4.04%

Original Filing — NVD Description

ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via a long ftp:// URI that leverages an existing session from the FTP client implementation in a web browser.