CVE-2006-3015: Code Injection
Published Jun 14, 2006
·Updated
Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or sftp URI.
Affected Software
2 affected components
WinSCP WinSCP=3.8.1_build328
WinSCP WinSCP=3.8.1
Event History
Jun 14, 2006
CVE Published
03:06 PM
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3015?
CVE-2006-3015 has been classified as having a medium severity rating due to its potential for file manipulation.
2
How do I fix CVE-2006-3015?
To fix CVE-2006-3015, users should upgrade to a later version of WinSCP beyond 3.8.1 build 328.
3
What versions of WinSCP are impacted by CVE-2006-3015?
CVE-2006-3015 affects WinSCP versions 3.8.1 build 328 and 3.8.1.
4
What attack vectors are associated with CVE-2006-3015?
CVE-2006-3015 can be exploited by using specially crafted SCP or SFTP URIs containing encoded spaces and double-quote characters.
5
Who is affected by CVE-2006-3015?
Any user utilizing WinSCP version 3.8.1 build 328 or 3.8.1 is potentially vulnerable to CVE-2006-3015.