curl/tests/data/test2116
Alhuda Khan 9494750986
ftp: reject control bytes in ACCT and alternative-to-user
A CR or LF in the CURLOPT_FTP_ACCOUNT or CURLOPT_FTP_ALTERNATIVE_TO_USER
string split the control-channel command line and smuggled a second FTP
command. Reject a byte below 0x20 in both values before the command is
built.

Closes #22301
2026-07-13 08:46:45 +02:00

45 lines
913 B
XML

<?xml version="1.0" encoding="US-ASCII"?>
<testcase>
<info>
<keywords>
FTP
--ftp-alternative-to-user
</keywords>
</info>
# Server-side
<reply>
<servercmd>
REPLY USER 530 go away
</servercmd>
</reply>
# Client-side
<client>
<server>
ftp
</server>
<name>
FTP --ftp-alternative-to-user with embedded CRLF is rejected
</name>
# read the command from a config file so the raw CR LF reaches curl intact
<file name="%LOGDIR/test%TESTNUMBER.config">
ftp-alternative-to-user = "USER me\r\nDELE %TESTNUMBER"
</file>
<command>
ftp://%HOSTIP:%FTPPORT/%TESTNUMBER/ -K %LOGDIR/test%TESTNUMBER.config
</command>
</client>
# Verify data after the test has been "shot"
<verify>
# 43 - CURLE_BAD_FUNCTION_ARGUMENT
<errorcode>
43
</errorcode>
# the replacement command is rejected before it is sent, so the injected DELE
# command must never reach the server
<protocol crlf="yes">
USER anonymous
</protocol>
</verify>
</testcase>