Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or sftp URI.
References
Configurations
History
No history.
Information
Published : 2006-06-14 15:06
Updated : 2025-04-03 01:03
NVD link : CVE-2006-3015
Mitre link : CVE-2006-3015
CVE.ORG link : CVE-2006-3015
JSON object : View
Products Affected
winscp
- winscp
CWE
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')