7.1
CVSSv2

CVE-2006-3015

Published: 14/06/2006 Updated: 13/02/2024
CVSS v2 Base Score: 7.1 | Impact Score: 9.2 | Exploitability Score: 4.9
VMScore: 715
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:N

Vulnerability Summary

Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote malicious users to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or sftp URI.

Vulnerable Product Search on Vulmon Subscribe to Product

winscp winscp 3.8.1

Exploits

source: wwwsecurityfocuscom/bid/18384/info WinSCP is prone to an arbitrary file-access vulnerability An attacker can exploit this issue to upload arbitrary files to a victim user's computer or to download arbitrary files from the victim's computer in the context of the vulnerable application This issue affects version 381; earlier ...