Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2019-6111
Disclosure Date: January 31, 2019 (last updated November 08, 2023)
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).
3
Attacker Value
Unknown
CVE-2018-20685
Disclosure Date: January 10, 2019 (last updated November 27, 2024)
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
1
Attacker Value
Unknown
CVE-2013-7474
Disclosure Date: August 01, 2019 (last updated November 27, 2024)
Windu CMS 2.2 allows XSS via the name parameter to admin/content/edit or admin/content/add, or the username parameter to admin/users.
0
Attacker Value
Unknown
CVE-2013-7473
Disclosure Date: August 01, 2019 (last updated November 27, 2024)
Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.
0
Attacker Value
Unknown
CVE-2019-6109
Disclosure Date: January 31, 2019 (last updated November 08, 2023)
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.
0
Attacker Value
Unknown
CVE-2017-1000219
Disclosure Date: November 17, 2017 (last updated November 26, 2024)
npm/KyleRoss windows-cpu all versions vulnerable to command injection resulting in code execution as Node.js user
0
Attacker Value
Unknown
CVE-2000-0892
Disclosure Date: July 21, 2001 (last updated February 22, 2025)
Some telnet clients allow remote telnet servers to request environment variables from the client that may contain sensitive information, or remote web servers to obtain the information via a telnet: URL.
0