Головна Банки Небанківський фінансовий сектор Кібершахрайство

CVE-2021-3331

WinSCP before 5.17.10 allows remote attackers to execute arbitrary programs when the URL handler encounters a crafted URL that loads session settings. (For example, this is exploitable in a default installation in which WinSCP is the handler for sftp:// URLs.)

Score

10

Source

http://nvd.nist.gov

Access-complexity

LOW

Access-vector

NETWORK