Vulnerabilities
Vulnerable Software
Scponly:  >> Scponly  >> 2.4  Security Vulnerabilities
The unison command in scponly before 4.0 does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via the (1) -rshcmd or (2) -sshcmd flags.
CVSS Score
7.5
EPSS Score
0.007
Published
2005-01-10
scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs and modifying the PATH variable in $HOME/.ssh/environment to locate those programs.
CVSS Score
7.5
EPSS Score
0.075
Published
2003-04-22


Contact Us

Shodan ® - All rights reserved