Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the server, potentially overwriting unrelated files. This affects TSCPFileSystem::SCPSink in core/ScpFileSystem.cpp.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WinSCP 输入验证漏洞
Vulnerability Description
WinSCP是捷克布拉格经济大学所开发与维护的一套在Windows环境下使用SSH的开源图形化SFTP和FTP客户端。该客户端支持SCP、SSH等协议,其主要功能是在本地与远程计算机间安全地复制文件,并且可以直接编辑文件。 WinSCP 5.14 beta之前版本中的core/ScpFileSystem.cpp文件的‘TSCPFileSystem::SCPSink’函数存在安全漏洞。攻击者可利用该漏洞覆盖不相关的文件。
CVSS Information
N/A
Vulnerability Type
N/A