7.5
CVSSv2

CVE-2002-1469

Published: 22/04/2003 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs and modifying the PATH variable in $HOME/.ssh/environment to locate those programs.

Vulnerable Product Search on Vulmon Subscribe to Product

scponly scponly 2.3

scponly scponly 2.4

Exploits

source: wwwsecurityfocuscom/bid/5526/info scponly is a freely available, open source restricted secure copy client It is available for Unix and Linux operating systems The default installation of scponly does not place sufficient access controls on the ssh subdirectory Due to this oversight, it is possible for a remote user to upload ...