WinSCP URI Handler Remote Arbitrary File Access Vulnerability

An attacker can exploit this issue by creating a malicious URI consisting if 'scp://' or 'sftp://' URI handlers.

The following proof-of-concept URIs are available:


 

Privacy Statement
Copyright 2010, SecurityFocus