Sploitus

CVE-2006-0225

1 known exploit for CVE-2006-0225

scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.

Affected products
Alt Linux, Hp-Ux, Openssh, Red Hat
Openbsd Openssh
= 3.0, 3.0.1, 3.0.1p1, 3.0.2, 3.0.2p1, 3.0p1, 3.1, 3.1p1, 3.2, 3.2.2p1, 3.2.3p1, 3.3, 3.3p1, 3.4, 3.4p1, 3.5, 3.5p1, 3.6, 3.6.1, 3.6.1p1, 3.6.1p2, 3.7, 3.7.1, 3.7.1p2, 3.8, 3.8.1, 3.8.1p1, 3.9, 3.9.1, 3.9.1p1, 4.0p1, 4.1p1, 4.2p1
Fix
Available
CVSS 2.0
4.6 MEDIUM
EPSS
0.5% (39th percentile)
NVD status
Modified
Published
2006-01-25
CVE-2006-0225 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2006-0225

Proof-of-concept code and exploit modules indexed by Sploitus