← Back

CVE-2009-3478

nvd nist
Published: Sep 29, 2009Modified: Apr 23, 2026

JSON object

Loading...
6.0
Vector
AV:N/AC:M/Au:S/C:P/I:P/A:P
Exploitability: 6.8 / Impact: 6.4
Source: NVD

Description

Argument injection vulnerability in (1) src/content/js/connection/sftp.js and (2) src/content/js/connection/controlSocket.js.in in FireFTP Extension 1.0.5 for Firefox allows remote authenticated SFTP users to cause victims to alter permissions, delete, download, or move the wrong file via a filename containing " (double quotes), which is not properly filtered or encoded when FireFTP constructs the command to send to psftp.exe.

Affected (1)

Products: Nightlight: Fireftp
1 product
Fireftp
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.0.5
Running on/withPlatform Versions
Mozilla
Firefox
All versions

Timeline

No history available yet.