20060310 WinSCP - URI Handler Command Switch Parsingmailing list
http://archives.neohapsis.com/archives/fulldisclosure/2006-06/0196.html CVE-2006-3015
WinSCP 3.8.1 - URI Handler Arbitrary File Access
Record summary
CVE-2006-3015 has a selected CVSS score of 7.1; EIP currently links 1 catalogued exploit.
Description
Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or sftp URI.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWinSCP 3.8.1 - URI Handler Arbitrary File AccessExploitDB exploitby Jelmer KuperusNot analyzed1 file
References
920060611 WinSCP - URI Handler Command Switch Parsingmailing list
http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/046810.html 20575Third-party advisory
http://secunia.com/advisories/20575 winscp.netConfirmation
http://winscp.net/eng/docs/history VU#912588Third-party advisory
http://www.kb.cert.org/vuls/id/912588 18384vdb entry
http://www.securityfocus.com/bid/18384 ADV-2006-2289vdb entry
http://www.vupen.com/english/advisories/2006/2289 winscp-uri-handler-command-execution(27075)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/27075 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2006-3015