Unrated severityNVD Advisory· Published Jun 14, 2006· Updated Apr 16, 2026
CVE-2006-3015
CVE-2006-3015
Description
Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or sftp URI.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- lists.grok.org.uk/pipermail/full-disclosure/2006-June/046810.htmlnvdBroken LinkExploit
- www.securityfocus.com/bid/18384nvdBroken LinkExploitThird Party AdvisoryVDB Entry
- secunia.com/advisories/20575nvdBroken LinkVendor Advisory
- www.kb.cert.org/vuls/id/912588nvdThird Party AdvisoryUS Government Resource
- exchange.xforce.ibmcloud.com/vulnerabilities/27075nvdThird Party AdvisoryVDB Entry
- archives.neohapsis.com/archives/fulldisclosure/2006-06/0196.htmlnvdBroken Link
- winscp.net/eng/docs/historynvdRelease Notes
- www.vupen.com/english/advisories/2006/2289nvdBroken Link
News mentions
0No linked articles in our index yet.