CVE-2006-0225
scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.
- Openbsd Openssh
- = 3.0, 3.0.1, 3.0.1p1, 3.0.2, 3.0.2p1, 3.0p1, 3.1, 3.1p1, 3.2, 3.2.2p1, 3.2.3p1, 3.3, 3.3p1, 3.4, 3.4p1, 3.5, 3.5p1, 3.6, 3.6.1, 3.6.1p1, 3.6.1p2, 3.7, 3.7.1, 3.7.1p2, 3.8, 3.8.1, 3.8.1p1, 3.9, 3.9.1, 3.9.1p1, 4.0p1, 4.1p1, 4.2p1
- Fix
- Available
- CVSS 2.0
- 4.6 MEDIUM
- EPSS
- 0.5% (39th percentile)
- NVD status
- Modified
- Published
- 2006-01-25
CVE-2006-0225 at NVD
1 known exploit for CVE-2006-0225
Proof-of-concept code and exploit modules indexed by Sploitus