scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
No PoCs from references.
- https://github.com/0day404/vulnerability-poc
- https://github.com/0xT11/CVE-POC
- https://github.com/0xb0rn3/r3cond0g
- https://github.com/20142995/sectool
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ArrestX/--POC
- https://github.com/CnHack3r/Penetration_PoC
- https://github.com/DeMeerleerGilles/NPE-Cybersecurity
- https://github.com/Devil-Gulshan/cybersecurity-intern-tasks-
- https://github.com/EchoGin404/-
- https://github.com/EchoGin404/gongkaishouji
- https://github.com/Evan-Zhangyf/CVE-2020-15778
- https://github.com/FontouraAbreu/seguranca-T5
- https://github.com/KayCHENvip/vulnerability-poc
- https://github.com/Lucky9113/Automated-Vulnerability-Scanner-Management-Tool
- https://github.com/MARNISAISATVIKA/SURE-Trust-Network-Penetration-Testing
- https://github.com/Maribel0370/Nebula-io
- https://github.com/Miraitowa70/POC-Notes
- https://github.com/Mr-xn/Penetration_Testing_POC
- https://github.com/Neko-chanQwQ/CVE-2020-15778-Exploit
- https://github.com/NeoOniX/5ATTACK
- https://github.com/NetW0rK1le3r/awesome-hacking-lists
- https://github.com/PuddinCat/GithubRepoSpider
- https://github.com/S3cur3Th1sSh1t/My-starred-Repositories
- https://github.com/SF4bin/SEEKER_dataset
- https://github.com/SexyBeast233/SecBooks
- https://github.com/SyedAfzalHussain/network-security-scanner
- https://github.com/TarikVUT/secure-fedora38
- https://github.com/Threekiii/Awesome-POC
- https://github.com/Totes5706/TotesHTB
- https://github.com/TrojanAZhen/Self_Back
- https://github.com/Tyro-Shan/gongkaishouji
- https://github.com/XiaomingX/awesome-poc-for-red-team
- https://github.com/YIXINSHUWU/Penetration_Testing_POC
- https://github.com/ZTK-009/Penetration_PoC
- https://github.com/aiswarya174/Elevate_labs_tasks_3
- https://github.com/austin-lai/External-Penetration-Testing-Holo-Corporate-Network-TryHackMe-Holo-Network
- https://github.com/chav00ooo/CYB333-Final-VulnerabilityScanner
- https://github.com/coffeewithcyber/rhel9.txt
- https://github.com/cpandya2909/CVE-2020-15778
- https://github.com/d4n-sec/d4n-sec.github.io
- https://github.com/developer3000S/PoC-in-GitHub
- https://github.com/drackyjr/CVE-2020-15778-SCP-Command-Injection-Check
- https://github.com/firatesatoglu/shodanSearch
- https://github.com/hackingyseguridad/ssha
- https://github.com/hak193/network-recon-tool
- https://github.com/hasee2018/Penetration_Testing_POC
- https://github.com/hectorgie/PoC-in-GitHub
- https://github.com/huike007/penetration_poc
- https://github.com/huisetiankong478/penetration_poc
- https://github.com/j1010756/Monthly-Creations
- https://github.com/jim091418/Information_Security_Course
- https://github.com/jithub07/vulnerability-scan-task
- https://github.com/krlabs/openssh-vulnerabilities
- https://github.com/lekctut/sdb-hw-13-01
- https://github.com/lions2012/Penetration_Testing_POC
- https://github.com/moffee-Puff/-Vulnerability-Scanner-using-Shodan-API
- https://github.com/n0-traces/cve_monitor
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/password520/Penetration_PoC
- https://github.com/pedr0alencar/vlab-metasploitable2
- https://github.com/pentration/gongkaishouji
- https://github.com/phanfivequ/xinminxuehui-milou-d46T7p3s8FIwKQp0
- https://github.com/phx/cvescan
- https://github.com/readloud/Awesome-Stars
- https://github.com/retr0-13/cveScannerV2
- https://github.com/scmanjarrez/CVEScannerV2
- https://github.com/siddicky/git-and-crumpets
- https://github.com/soosmile/POC
- https://github.com/winterwolf32/CVE-S---Penetration_Testing_POC-
- https://github.com/wooflock/nmap-airgapped-vulnscan
- https://github.com/xbl2022/awesome-hacking-lists
- https://github.com/xuetusummer/Penetration_Testing_POC
- https://github.com/yedada-wei/-
- https://github.com/yedada-wei/gongkaishouji