Описание
Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or sftp URI.
Ссылки
- Broken Link
- Broken LinkExploit
- Broken LinkVendor Advisory
- Release Notes
- Third Party AdvisoryUS Government Resource
- Broken LinkExploitThird Party AdvisoryVDB Entry
- Broken Link
- Third Party AdvisoryVDB Entry
- Broken Link
- Broken LinkExploit
- Broken LinkVendor Advisory
- Release Notes
- Third Party AdvisoryUS Government Resource
- Broken LinkExploitThird Party AdvisoryVDB Entry
- Broken Link
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:winscp:winscp:3.8.1:*:*:*:*:*:*:*
EPSS
Процентиль: 95%
0.1757
Средний
7.1 High
CVSS2
Дефекты
CWE-88
Связанные уязвимости
github
почти 4 года назад
Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or sftp URI.
EPSS
Процентиль: 95%
0.1757
Средний
7.1 High
CVSS2
Дефекты
CWE-88