Scponly

Scponly

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.84%
  • Veröffentlicht 14.12.2007 20:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute code by invoking dangerous subcommands including (1) unison, (2) rsync, (3) svn, and (4) svnserve, as originally demonstrated by creating a Subversi...

  • EPSS 0.06%
  • Veröffentlicht 28.12.2005 01:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

scponlyc in scponly 4.1 and earlier, when the operating system supports LD_PRELOAD mechanisms, allows local users to execute arbitrary code with root privileges by creating a chroot directory in their home directory, hard linking to a system setuid a...

  • EPSS 0.63%
  • Veröffentlicht 28.12.2005 01:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Argument injection vulnerability in scponlyc in scponly 4.1 and earlier, when both scp and rsync compatibility are enabled, allows local users to execute arbitrary applications via "getopt" style argument specifications, which are not filtered.

Exploit
  • EPSS 0.65%
  • Veröffentlicht 10.01.2005 05:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The unison command in scponly before 4.0 does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via the (1) -rshcmd or (2) -sshcmd flags.

Exploit
  • EPSS 7.53%
  • Veröffentlicht 22.04.2003 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs and modifying the PATH variable in $HOME/.ssh/envir...