Vulnerabilities
Vulnerable Software
Scponly:  >> Scponly  >> 3.11  Security Vulnerabilities
scponlyc in scponly 4.1 and earlier, when the operating system supports LD_PRELOAD mechanisms, allows local users to execute arbitrary code with root privileges by creating a chroot directory in their home directory, hard linking to a system setuid application, and using a modified LD_PRELOAD to modify expected function calls in the setuid application.
CVSS Score
7.2
EPSS Score
0.001
Published
2005-12-28
Argument injection vulnerability in scponlyc in scponly 4.1 and earlier, when both scp and rsync compatibility are enabled, allows local users to execute arbitrary applications via "getopt" style argument specifications, which are not filtered.
CVSS Score
7.5
EPSS Score
0.006
Published
2005-12-28
The unison command in scponly before 4.0 does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via the (1) -rshcmd or (2) -sshcmd flags.
CVSS Score
7.5
EPSS Score
0.007
Published
2005-01-10


Contact Us

Shodan ® - All rights reserved