Vulnerability Description
Argument injection vulnerability in (1) src/content/js/connection/sftp.js and (2) src/content/js/connection/controlSocket.js.in in FireFTP Extension 1.0.5 for Firefox allows remote authenticated SFTP users to cause victims to alter permissions, delete, download, or move the wrong file via a filename containing " (double quotes), which is not properly filtered or encoded when FireFTP constructs the command to send to psftp.exe.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nightlight | Fireftp | 1.0.5 |
| Mozilla | Firefox | All versions |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/36860Vendor Advisory
- http://vuln.sg/fireftp105-en.htmlExploit
- http://www.mozdev.org/source/browse/fireftp/src/content/js/connection/controlSoc
- http://www.mozdev.org/source/browse/fireftp/src/content/js/connection/controlSoc
- http://www.mozdev.org/source/browse/fireftp/src/content/js/connection/sftp.js.di
- http://www.securityfocus.com/bid/36536Patch
- http://secunia.com/advisories/36860Vendor Advisory
- http://vuln.sg/fireftp105-en.htmlExploit
- http://www.mozdev.org/source/browse/fireftp/src/content/js/connection/controlSoc
- http://www.mozdev.org/source/browse/fireftp/src/content/js/connection/controlSoc
- http://www.mozdev.org/source/browse/fireftp/src/content/js/connection/sftp.js.di
- http://www.securityfocus.com/bid/36536Patch
FAQ
What is CVE-2009-3478?
CVE-2009-3478 is a vulnerability with a CVSS score of 6.0 (MEDIUM). Argument injection vulnerability in (1) src/content/js/connection/sftp.js and (2) src/content/js/connection/controlSocket.js.in in FireFTP Extension 1.0.5 for Firefox allows remote authenticated SFTP ...
How severe is CVE-2009-3478?
CVE-2009-3478 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-3478?
Check the references section above for vendor advisories and patch information. Affected products include: Nightlight Fireftp, Mozilla Firefox.