Vulnerability Name: | CVE-2006-3015 (CCN-27075) | ||||||||
Assigned: | 2006-06-10 | ||||||||
Published: | 2006-06-10 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or sftp URI. | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.1 High (CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:N) 5.2 Medium (Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:N/E:U/RL:OF/RC:C)
5.6 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-94 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Fri Mar 10 2006 - 14:24:12 CST WinSCP - URI Handler Command Switch Parsing Source: FULLDISC Type: UNKNOWN 20060310 WinSCP - URI Handler Command Switch Parsing Source: MITRE Type: CNA CVE-2006-3015 Source: FULLDISC Type: Exploit 20060611 WinSCP - URI Handler Command Switch Parsing Source: CCN Type: SA20575 WinSCP Protocol Handler Command Line Switch Injection Source: SECUNIA Type: Vendor Advisory 20575 Source: CONFIRM Type: UNKNOWN http://winscp.net/eng/docs/history#3.8.2 Source: CCN Type: WinSCP Web site WinSCP :: Freeware SFTP and SCP client for WIndows Source: CCN Type: US-CERT VU#912588 WinSCP URI handlers fails to properly parse command line switches Source: CERT-VN Type: US Government Resource VU#912588 Source: CCN Type: OSVDB ID: 26338 WinSCP scp/sftp Protocol Handler Arbitrary Command Injection Source: CCN Type: OSVDB ID: 40519 WinSCP Protocol Handler Command Line Switch Injection Arbitrary File Transfer Source: BID Type: Exploit 18384 Source: CCN Type: BID-18384 WinSCP URI Handler Remote Arbitrary File Access Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-2289 Source: XF Type: UNKNOWN winscp-uri-handler-command-execution(27075) Source: XF Type: UNKNOWN winscp-uri-handler-command-execution(27075) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |