vendor:
tnftp
by:
dash
7,5
CVSS
HIGH
tnftp exploit
20
CWE
Product Name: tnftp
Affected Version From: FreeBSD 8/9/10
Affected Version To: FreeBSD 9.3
Patch Exists: YES
Related CWE: CVE-2014-8517
CPE: a:freebsd:freebsd
Metasploit:
https://www.rapid7.com/db/vulnerabilities/apple-osx-lukemftp-cve-2014-8517/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-7488378d-6007-11e6-a6c3-14dae9d210b8/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2014-8517/, https://www.rapid7.com/db/vulnerabilities/apple-osx-afpserver-cve-2014-8517/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2014-8517/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD 9.3
2014
tnftp BSD exploit
This exploit is a python script that takes advantage of a vulnerability in tnftp, a BSD FTP client. It redirects the vulnerable FTP client requests for http to the attacker's machine, and then delivers a malicious payload to the victim.
Mitigation:
The vulnerability can be mitigated by upgrading to the latest version of tnftp.