Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SCPOnly SSH Environment Shell Escaping Vulnerability

scponly is a freely available, open source restricted secure copy client. It is available for Unix and Linux operating systems.

The default installation of scponly does not place sufficient access controls on the .ssh subdirectory. Due to this oversight, it is possible for a remote user to upload files which may allow command execution. This could lead to unintended command execution, and regular shell access to a vulnerable host.







 

Privacy Statement
Copyright 2008, SecurityFocus