Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-15778
Description:** DISPUTED ** scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
Test IDs: 1.3.6.1.4.1.25623.1.1.2.2021.2018   1.3.6.1.4.1.25623.1.1.2.2021.2039   1.3.6.1.4.1.25623.1.1.2.2021.1993   1.3.6.1.4.1.25623.1.1.2.2021.2097   1.3.6.1.4.1.25623.1.0.113736  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-15778
https://security.gentoo.org/glsa/202212-06
https://access.redhat.com/errata/RHSA-2024:3166
https://github.com/cpandya2909/CVE-2020-15778/
https://news.ycombinator.com/item?id=25005567
https://www.openssh.com/security.html




© 1998-2025 E-Soft Inc. All rights reserved.