CVE-2020-15778
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
- Openbsd Openssh
- < 8.3
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 13.0% (96th percentile)
- Weakness
- CWE-78
- NVD status
- Analyzed
- Published
- 2020-07-24
CVE-2020-15778 at NVD
9 known exploits for CVE-2020-15778
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2020-15778-Exploit
CVE-2020-15778
CVE-2020-15778
CVE-2020-15778-SCP-Command-Injection-Check
Exploit for Path Traversal in Openbsd Openssh
Exploit for OS Command Injection in Openbsd Openssh
Exploit for OS Command Injection in Openbsd Openssh
Exploit for OS Command Injection in Openbsd Openssh
Exploit for OS Command Injection in Openbsd Openssh