CVE-2000-0992

OpenSSH - Directory Traversal via Malicious SCP Server

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0992. PoCs published by Michal Zalewski.

AI-analyzed exploit summary This exploit demonstrates a path traversal vulnerability in scp 1.2.x, where a malicious server can overwrite arbitrary files on the client by sending manipulated filenames. The PoC replaces the server-side scp binary to create a setuid file in /tmp on the client.

Description

Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Michal Zalewski · bashremotelinux
https://www.exploit-db.com/exploits/20253

This exploit demonstrates a path traversal vulnerability in scp 1.2.x, where a malicious server can overwrite arbitrary files on the client by sending manipulated filenames. The PoC replaces the server-side scp binary to create a setuid file in /tmp on the client.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: scp 1.2.x
Auth required
Prerequisites: Access to a server running scp 1.2.x · Ability to replace the server-side scp binary
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5312
Various Sources vendor-advisory x_refsource_mandrake
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:057
Exploit, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-09/0359.html
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1742

Scores

EPSS 0.0567
EPSS Percentile 92.0%

Details

Status published
Products (20)
openbsd/openssh 1.2
openbsd/openssh 1.2.3
ssh/ssh 1.2.14
ssh/ssh 1.2.15
ssh/ssh 1.2.16
ssh/ssh 1.2.17
ssh/ssh 1.2.18
ssh/ssh 1.2.19
ssh/ssh 1.2.20
ssh/ssh 1.2.21
... and 10 more
Published Dec 19, 2000
Tracked Since Feb 18, 2026