EIP-2026-119287
PRE-CVEWinSCP 3.5.6 - Long URI Handling Memory Corruption
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-119287. PoCs published by Luca Ercoli.
AI-analyzed exploit summary The exploit demonstrates a denial-of-service (DoS) vulnerability in WinSCP by triggering memory corruption via excessively long 'sftp:' or 'scp' addresses. The provided HTML files leverage either a meta refresh or a VBScript to launch WinSCP with a malformed URI, causing the application to crash.
Description
WinSCP 3.5.6 - Long URI Handling Memory Corruption
Exploits (1)
The exploit demonstrates a denial-of-service (DoS) vulnerability in WinSCP by triggering memory corruption via excessively long 'sftp:' or 'scp' addresses. The provided HTML files leverage either a meta refresh or a VBScript to launch WinSCP with a malformed URI, causing the application to crash.