CVE-2006-0225

Modified
Published: 25 Jan 2006, 11:00
Last modified:07 Aug 2024, 16:25

Vulnerability Summary

Overall Risk (default)
low
18/100
CVSS Score
4.6 MEDIUM
v2.0 (nvd)
EPSS Score
0.09% LOW
0% probability -0.03%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

25 Jan 2006, 11:00
Published
Vulnerability first disclosed
07 Aug 2024, 16:25
Last Modified
Vulnerability information updated

Description

scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.

CVSS Metrics

  • v2.0MEDIUMScore: 4.6AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 0.09% Percentile: 26%

Affected Systems

  • openbsdopenssh

    3.0 | 3.0.1 | 3.0.1p1 | 3.0.2 | 3.0.2p1 | 3.0p1 | 3.1 | 3.1p1 | 3.2 | 3.2.2p1 | 3.2.3p1 | 3.3 | 3.3p1 | 3.4 | 3.4p1 | 3.5 | 3.5p1 | 3.6 | 3.6.1 | 3.6.1p1 | 3.6.1p2 | 3.7 | 3.7.1 | 3.7.1p2 | 3.8 | 3.8.1 | 3.8.1p1 | 3.9 | 3.9.1 | 3.9.1p1 | 4.0p1 | 4.1p1 | 4.2p1

References (64)