Vulnerabilities > CVE-2002-1469 - Unspecified vulnerability in Scponly 2.3/2.4

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
scponly
exploit available

Summary

scponly does not properly verify the path when finding the (1) scp or (2) sftp-server programs, which could allow remote authenticated users to bypass access controls by uploading malicious programs and modifying the PATH variable in $HOME/.ssh/environment to locate those programs.

Vulnerable Configurations

Part Description Count
Application
Scponly
2

Exploit-Db

descriptionSCPOnly 2.3/2.4 SSH Environment Shell Escaping Vulnerability. CVE-2002-1469. Local exploit for linux platform
idEDB-ID:21732
last seen2016-02-02
modified2002-08-20
published2002-08-20
reporterDerek D. Martin
sourcehttps://www.exploit-db.com/download/21732/
titleSCPOnly 2.3/2.4 - SSH Environment Shell Escaping Vulnerability