CVE-2016-5725
CVE-2016-5725
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a recursive GET command.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/138809/jsch-0.1.53-Path-Traversal.htmlunverifiedcve_referencewww.exploit-db.com/exploits/40411/unverifiedexploitdbwww.exploit-db.com/exploits/40411unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://packetstormsecurity.com/files/138809/jsch-0.1.53-Path-Traversal.htmlhttps://access.redhat.com/errata/RHSA-2017:3115http://seclists.org/fulldisclosure/2016/Sep/53https://github.com/tintinweb/pub/tree/master/pocs/cve-2016-5725https://lists.debian.org/debian-lts-announce/2020/04/msg00017.htmlhttps://www.exploit-db.com/exploits/40411/https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttp://www.jcraft.com/jsch/ChangeLoghttp://www.securityfocus.com/bid/93100