Vulnerabilities > CVE-2002-1469 - Unspecified vulnerability in Scponly 2.3/2.4

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
scponly
exploit available

Summary

scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs and modifying the PATH variable in $HOME/.ssh/environment to locate those programs.

Vulnerable Configurations

Part Description Count
Application
Scponly
2

Exploit-Db

descriptionSCPOnly 2.3/2.4 SSH Environment Shell Escaping Vulnerability. CVE-2002-1469. Local exploit for linux platform
idEDB-ID:21732
last seen2016-02-02
modified2002-08-20
published2002-08-20
reporterDerek D. Martin
sourcehttps://www.exploit-db.com/download/21732/
titleSCPOnly 2.3/2.4 - SSH Environment Shell Escaping Vulnerability