vendor:
KDE FTP kioslave-based Applications
by:
7.5
CVSS
HIGH
Arbitrary Command Execution
20
CWE
Product Name: KDE FTP kioslave-based Applications
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux, Unix
Arbitrary FTP Server Command Execution in KDE FTP kioslave-based Applications
KDE FTP kioslave-based applications such as Konqueror are reported prone to an arbitrary FTP server command execution vulnerability. This issue allows attackers to embed arbitrary FTP server commands in malicious URIs, leading to the execution of these commands on remote servers. Attackers can exploit this vulnerability to download malicious files to the victim's computer or send email to arbitrary addresses without user interaction.
Mitigation:
Apply the vendor-provided patch or upgrade to a non-vulnerable version of the software. Avoid clicking on suspicious links or accessing malicious URIs.