CVE-2016-5725 – JCraft/JSch Java Secure Channel <= 0.1.53 recursive sftp-get path traversal (client-side, windows)

Posted by oststrom (public) on Sep 21

Ref: https://github.com/tintinweb/pub/tree/master/pocs/cve-2016-5725
Version: 0.3
Date: Aug 31st, 2016

Tag: jsch recursive sftp get client-side windows path traversal

Overview
——–

Name: jsch
Vendor: jcraft
References: * http://www.jcraft.com/jsch/ [1]

Version: 0.1.53 [2]
Latest Version: 0.1.54 [2]
Other Versions: <= 0.1.53
Platform(s): windows
Technology: java

Vuln Classes:…

Leave a Reply