Martin Prikryl

2 exploits Active since Jan 2019
CVE-2018-20684 WRITEUP HIGH WRITEUP
Winscp < 5.13.7 - Improper Input Validation
In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the server, potentially overwriting unrelated files. This affects TSCPFileSystem::SCPSink in core/ScpFileSystem.cpp.
CVSS 7.5
CVE-2021-3331 WRITEUP CRITICAL WRITEUP
WinSCP <5.17.10 - RCE
WinSCP before 5.17.10 allows remote attackers to execute arbitrary programs when the URL handler encounters a crafted URL that loads session settings. (For example, this is exploitable in a default installation in which WinSCP is the handler for sftp:// URLs.)
CVSS 9.8