Synced 17 Jun 2026 22:27 UTC Account
← All products

CVE-2006-3015

HIGH severity · CVSS 7.1 · CWE-88
7.1CVSS HIGH

Summary

Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or sftp URI.

Impact & exploitability

Attack vectorNetwork
Attack complexityHigh
Privileges required
User interaction
Confidentiality impact
Integrity impact
Availability impactNone
Exploit probability (EPSS)6%

AV:N/AC:H/Au:N/C:C/I:C/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.